<?xml version="1.0" encoding="UTF-8"?>
<oval_definitions xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-definitions-5 oval-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5#windows windows-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5#independent independent-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-common-5 oval-common-schema.xsd" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:oval="http://oval.mitre.org/XMLSchema/oval-common-5" xmlns:oval-def="http://oval.mitre.org/XMLSchema/oval-definitions-5">
  <generator>
    <oval:product_name>The OVAL Repository</oval:product_name>
    <oval:schema_version>5.4</oval:schema_version>
    <oval:timestamp>2015-09-03T06:35:41.480-04:00</oval:timestamp>
  </generator>
  <definitions>
    <definition id="oval:org.mitre.oval:def:29493" version="3" class="vulnerability">
      <metadata>
        <title>OpenType font driver vulnerability - CVE-2015-2426 (MS15-078)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-2426" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2426"/>
        <description>Buffer underflow in atmfd.dll in the Windows Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to execute arbitrary code via a crafted OpenType font, aka "OpenType Font Driver Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-07-22T13:00:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-07-23T11:33:46.957-04:00">DRAFT</status_change>
            <status_change date="2015-08-10T04:00:57.541-04:00">INTERIM</status_change>
            <status_change date="2015-08-31T04:00:28.008-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Vista/2k8/Win7/2k8 R2/ Win 8/2k12/Win 8.1/2k12 R2">
          <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
          <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
          <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
          <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
          <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
          <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
          <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
          <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
          <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
        </criteria>
        <criterion comment="Check if the version of atmfd.dll is less than 5.1.2.243" test_ref="oval:org.mitre.oval:tst:141149"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29470" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-2414 (MS15-065)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-2414" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2414" source="CVE"/>
        <description>Microsoft Internet Explorer 8 through 11 allows remote attackers to obtain sensitive browsing-history information via vectors related to image caching, aka "Internet Explorer Information Disclosure Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-07-22T13:00:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-07-23T11:16:13.594-04:00">DRAFT</status_change>
            <status_change date="2015-08-10T04:00:56.809-04:00">INTERIM</status_change>
            <status_change date="2015-08-31T04:00:27.211-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23707" test_ref="oval:org.mitre.oval:tst:141287"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19652" test_ref="oval:org.mitre.oval:tst:141242"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23707" test_ref="oval:org.mitre.oval:tst:141287"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18896" test_ref="oval:org.mitre.oval:tst:141220"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.23099" test_ref="oval:org.mitre.oval:tst:141285"/>
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.23000" test_ref="oval:org.mitre.oval:tst:138202"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16669" test_ref="oval:org.mitre.oval:tst:141203"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20784" test_ref="oval:org.mitre.oval:tst:141111"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17412" test_ref="oval:org.mitre.oval:tst:140758"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21523" test_ref="oval:org.mitre.oval:tst:141225"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17905" test_ref="oval:org.mitre.oval:tst:141110"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29454" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer elevation of privilege vulnerability - CVE-2015-2402 (MS15-065)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-2402" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2402" source="CVE"/>
        <description>Microsoft Internet Explorer 7 through 11 allows remote attackers to gain privileges via a crafted web site, aka "Internet Explorer Elevation of Privilege Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-07-22T13:00:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-07-23T11:15:58.714-04:00">DRAFT</status_change>
            <status_change date="2015-08-10T04:00:56.432-04:00">INTERIM</status_change>
            <status_change date="2015-08-31T04:00:26.887-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21481" test_ref="oval:org.mitre.oval:tst:140959"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista / 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19421" test_ref="oval:org.mitre.oval:tst:140954"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23728" test_ref="oval:org.mitre.oval:tst:141086"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23707" test_ref="oval:org.mitre.oval:tst:141287"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19652" test_ref="oval:org.mitre.oval:tst:141242"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23707" test_ref="oval:org.mitre.oval:tst:141287"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18896" test_ref="oval:org.mitre.oval:tst:141220"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.23099" test_ref="oval:org.mitre.oval:tst:141285"/>
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.23000" test_ref="oval:org.mitre.oval:tst:138202"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16669" test_ref="oval:org.mitre.oval:tst:141203"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20784" test_ref="oval:org.mitre.oval:tst:141111"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17412" test_ref="oval:org.mitre.oval:tst:140758"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21523" test_ref="oval:org.mitre.oval:tst:141225"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17905" test_ref="oval:org.mitre.oval:tst:141110"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29436" version="3" class="vulnerability">
      <metadata>
        <title>Win32k Elevation of privilege vulnerability - CVE-2015-2363 (MS15-073)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-2363" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2363"/>
        <description>win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012, and Windows RT allows local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-07-22T16:53:08">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-07-23T11:25:54.125-04:00">DRAFT</status_change>
            <status_change date="2015-08-10T04:00:55.626-04:00">INTERIM</status_change>
            <status_change date="2015-08-31T04:00:25.993-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Windows Server 2k3 and vulnerable file version">
          <criteria operator="OR" comment="Either OS">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of win32k.sys is less than 5.2.3790.5667" test_ref="oval:org.mitre.oval:tst:141098"/>
        </criteria>
        <criteria operator="AND" comment="Vista / 2k8 + vulnerable file version">
          <criteria operator="OR" comment="Vista / 2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.0.6002.19429" test_ref="oval:org.mitre.oval:tst:141152"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:81723"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.0.6002.23735" test_ref="oval:org.mitre.oval:tst:141262"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / R2 + vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.18906" test_ref="oval:org.mitre.oval:tst:141244"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:81763"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.23109" test_ref="oval:org.mitre.oval:tst:141301"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8/2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.17419" test_ref="oval:org.mitre.oval:tst:141068"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:115678"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.21528" test_ref="oval:org.mitre.oval:tst:141153"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29431" version="3" class="vulnerability">
      <metadata>
        <title>Windows installer EoP vulnerability - CVE-2015-2371 (MS15-074)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Vista</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-2371" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2371"/>
        <description>The Windows Installer service in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges via a custom action script associated with a .msi package, aka "Windows Installer EoP Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-07-22T12:06:54">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-07-23T11:27:30.824-04:00">DRAFT</status_change>
            <status_change date="2015-08-10T04:00:55.162-04:00">INTERIM</status_change>
            <status_change date="2015-08-31T04:00:25.728-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista SP2 x86/x64, Server 2008 SP2 32bit/x64/ia64">
          <criteria operator="OR" comment="Check for vulnerable Microsoft Windows OS">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="Check if the version of msi.dll is less than 4.5.6002.19424" test_ref="oval:org.mitre.oval:tst:140643"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="Check if the version of msi.dll is greater than or equal to 4.5.6002.23000" test_ref="oval:org.mitre.oval:tst:140917"/>
              <criterion comment="Check if the version of msi.dll is less than 4.5.6002.23730" test_ref="oval:org.mitre.oval:tst:141315"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 7 x86/x64, Server 2008 R2 x64/ia64">
          <criteria operator="OR" comment="Check for vulnerable Microsoft Windows OS">
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="Check if the version of msi.dll is less than 5.0.7601.18896" test_ref="oval:org.mitre.oval:tst:141258"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="Check if the version of msi.dll is greater than or equal to 5.0.7601.23000" test_ref="oval:org.mitre.oval:tst:140322"/>
              <criterion comment="Check if the version of msi.dll is less than 5.0.7601.23099" test_ref="oval:org.mitre.oval:tst:141164"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="8.1/2012 R2 and vulnerable version">
          <criteria operator="OR" comment="8.1/ 2012 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of msi.dll is less than 5.0.9600.17905" test_ref="oval:org.mitre.oval:tst:140784"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 2K3">
          <criteria operator="OR" comment="Check for vulnerable Microsoft Windows OS">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of msi.dll is less than 4.5.6002.23731" test_ref="oval:org.mitre.oval:tst:141276"/>
        </criteria>
        <criteria operator="AND" comment="Win 8 / 2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criteria operator="AND" comment="Check for LDR range">
              <criterion comment="Check if the version of msi.dll is less than 5.0.9200.21523" test_ref="oval:org.mitre.oval:tst:141175"/>
              <criterion comment="Check if the version of msi.dll is greater than or equal to 5.0.9200.21000" test_ref="oval:org.mitre.oval:tst:141015"/>
            </criteria>
            <criterion comment="Check if the version of msi.dll is less than 5.0.9200.17412" test_ref="oval:org.mitre.oval:tst:141240"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29422" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer information disclosure vulnerability - CVE-2015-2413 (MS15-065)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-2413" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2413" source="CVE"/>
        <description>Microsoft Internet Explorer 6 through 11 allows remote attackers to determine the existence of local files via a crafted module-resource request, aka "Internet Explorer Information Disclosure Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-07-22T13:00:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-07-23T11:15:56.062-04:00">DRAFT</status_change>
            <status_change date="2015-08-10T04:00:54.512-04:00">INTERIM</status_change>
            <status_change date="2015-08-31T04:00:25.262-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5662" test_ref="oval:org.mitre.oval:tst:140298"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21481" test_ref="oval:org.mitre.oval:tst:140959"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista / 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19421" test_ref="oval:org.mitre.oval:tst:140954"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23728" test_ref="oval:org.mitre.oval:tst:141086"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23707" test_ref="oval:org.mitre.oval:tst:141287"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19652" test_ref="oval:org.mitre.oval:tst:141242"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23707" test_ref="oval:org.mitre.oval:tst:141287"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18896" test_ref="oval:org.mitre.oval:tst:141220"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.23099" test_ref="oval:org.mitre.oval:tst:141285"/>
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.23000" test_ref="oval:org.mitre.oval:tst:138202"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16669" test_ref="oval:org.mitre.oval:tst:141203"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20784" test_ref="oval:org.mitre.oval:tst:141111"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17412" test_ref="oval:org.mitre.oval:tst:140758"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21523" test_ref="oval:org.mitre.oval:tst:141225"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17905" test_ref="oval:org.mitre.oval:tst:141110"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29406" version="3" class="vulnerability">
      <metadata>
        <title>Hyper-V system data structure vulnerability - CVE-2015-2362 (MS15-068)</title>
        <affected family="windows">
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2008</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-2362" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2362"/>
        <description>Hyper-V in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 does not properly initialize guest OS system data structures, which allows guest OS users to execute arbitrary code on the host OS by leveraging guest OS privileges, aka "Hyper-V System Data Structure Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-07-22T12:38:03">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-07-23T11:18:46.949-04:00">DRAFT</status_change>
            <status_change date="2015-08-10T04:00:54.045-04:00">INTERIM</status_change>
            <status_change date="2015-08-31T04:00:24.594-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Win 8.1 / 2k12 and vulnerable file version">
          <criteria operator="OR" comment="8.1 / 2k12">
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of vmicvss.dll is less than 6.3.9600.17723" test_ref="oval:org.mitre.oval:tst:141277"/>
        </criteria>
        <criteria operator="AND" comment="2k8 and vulnerable file version">
          <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of vmicvss.dll is less than 6.0.6002.19378" test_ref="oval:org.mitre.oval:tst:141275"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of vmicvss.dll is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:141253"/>
              <criterion comment="Check if the version of vmicvss.dll is less than 6.0.6002.23684" test_ref="oval:org.mitre.oval:tst:141040"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="R2 x64 and vulnerable file version">
          <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of vmicvss.dll is less than 6.1.7601.18844" test_ref="oval:org.mitre.oval:tst:140965"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of vmicvss.dll is greater than or equal to 6.1.7601.23000" test_ref="oval:org.mitre.oval:tst:141216"/>
              <criterion comment="Check if the version of vmicvss.dll is less than 6.1.7601.23045" test_ref="oval:org.mitre.oval:tst:141089"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8 / 2k12 (x64) and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of vmicvss.dll is less than 6.2.9200.17361" test_ref="oval:org.mitre.oval:tst:141232"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of vmicvss.dll is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:141131"/>
              <criterion comment="Check if the version of vmicvss.dll is less than 6.2.9200.21473" test_ref="oval:org.mitre.oval:tst:140470"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29395" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-2389 (MS15-065)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-2389" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2389" source="CVE"/>
        <description>Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-1733 and CVE-2015-2411.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-07-22T13:00:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-07-23T11:16:42.224-04:00">DRAFT</status_change>
            <status_change date="2015-08-10T04:00:53.843-04:00">INTERIM</status_change>
            <status_change date="2015-08-31T04:00:24.385-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17412" test_ref="oval:org.mitre.oval:tst:140758"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21523" test_ref="oval:org.mitre.oval:tst:141225"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17905" test_ref="oval:org.mitre.oval:tst:141110"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29392" version="3" class="vulnerability">
      <metadata>
        <title>Remote Desktop Protocol (RDP) remote code execution vulnerability - CVE-2015-2373 (MS15-067)</title>
        <affected family="windows">
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 7</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-2373" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2373"/>
        <description>The Remote Desktop Protocol (RDP) server service in Microsoft Windows 7 SP1, Windows 8, and Windows Server 2012 allows remote attackers to execute arbitrary code via a series of crafted packets, aka "Remote Desktop Protocol (RDP) Remote Code Execution Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-07-22T09:38:04">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-07-24T08:15:21.344-04:00">DRAFT</status_change>
            <status_change date="2015-08-10T04:00:53.339-04:00">INTERIM</status_change>
            <status_change date="2015-08-31T04:00:23.995-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Win 7 / R2 + vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of rdpcorets.dll is less than 6.1.7601.18892" test_ref="oval:org.mitre.oval:tst:140861"/>
            <criteria operator="AND" comment="LDR range">
              <criterion comment="Check if the version of rdpcorets.dll is less than 6.1.7601.23095" test_ref="oval:org.mitre.oval:tst:140926"/>
              <criterion comment="Check if the version of rdpcorets.dll is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:114959"/>
            </criteria>
            <criteria operator="AND" comment="rdpcorets.dll with version range 6.2.9200.xxxx">
              <criteria operator="OR" comment="gdr/ldr">
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of rdpcorets.dll is less than 6.2.9200.21506" test_ref="oval:org.mitre.oval:tst:141412"/>
                  <criterion comment="Check if the version of rdpcorets.dll is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:114938"/>
                </criteria>
                <criterion comment="Check if the version of rdpcorets.dll is less than 6.2.9200.17395" test_ref="oval:org.mitre.oval:tst:141388"/>
              </criteria>
              <criterion comment="Check if the version of rdpcorets.dll is greater than or equal to 6.2.9200.00000" test_ref="oval:org.mitre.oval:tst:137511"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8/2k12 and vulnerable file version">
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of rdpcorets.dll is less than 6.2.9200.17395" test_ref="oval:org.mitre.oval:tst:141388"/>
            <criteria operator="AND" comment="Check for LDR range">
              <criterion comment="Check if the version of rdpcorets.dll is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:114938"/>
              <criterion comment="Check if the version of rdpcorets.dll is less than 6.2.9200.21506" test_ref="oval:org.mitre.oval:tst:141412"/>
            </criteria>
          </criteria>
          <criteria operator="OR" comment="Win 8 (32 / 64) and 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29388" version="3" class="vulnerability">
      <metadata>
        <title>Win32k information disclosure vulnerability - CVE-2015-2381 (MS15-073)</title>
        <affected family="windows">
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-2381" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2381"/>
        <description>win32k.sys in the kernel-mode drivers in Microsoft Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to obtain sensitive information from kernel memory via a crafted application, aka "Win32k Information Disclosure Vulnerability," a different vulnerability than CVE-2015-2382.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-07-22T16:53:08">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-07-23T11:25:52.484-04:00">DRAFT</status_change>
            <status_change date="2015-08-10T04:00:52.930-04:00">INTERIM</status_change>
            <status_change date="2015-08-31T04:00:23.588-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Win 8/2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.17419" test_ref="oval:org.mitre.oval:tst:141068"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:115678"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.21528" test_ref="oval:org.mitre.oval:tst:141153"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1 / 2K12 R2and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of win32k.sys is less than 6.3.9600.17915" test_ref="oval:org.mitre.oval:tst:141251"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29360" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-2422 (MS15-065)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-2422" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2422" source="CVE"/>
        <description>Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-2385, CVE-2015-2390, CVE-2015-2397, CVE-2015-2404, and CVE-2015-2406.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-07-22T13:00:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-07-23T11:16:11.475-04:00">DRAFT</status_change>
            <status_change date="2015-08-10T04:00:52.125-04:00">INTERIM</status_change>
            <status_change date="2015-08-31T04:00:23.223-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5662" test_ref="oval:org.mitre.oval:tst:140298"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21481" test_ref="oval:org.mitre.oval:tst:140959"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista / 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19421" test_ref="oval:org.mitre.oval:tst:140954"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23728" test_ref="oval:org.mitre.oval:tst:141086"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23707" test_ref="oval:org.mitre.oval:tst:141287"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19652" test_ref="oval:org.mitre.oval:tst:141242"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23707" test_ref="oval:org.mitre.oval:tst:141287"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18896" test_ref="oval:org.mitre.oval:tst:141220"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.23099" test_ref="oval:org.mitre.oval:tst:141285"/>
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.23000" test_ref="oval:org.mitre.oval:tst:138202"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16669" test_ref="oval:org.mitre.oval:tst:141203"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20784" test_ref="oval:org.mitre.oval:tst:141111"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17412" test_ref="oval:org.mitre.oval:tst:140758"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21523" test_ref="oval:org.mitre.oval:tst:141225"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17905" test_ref="oval:org.mitre.oval:tst:141110"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29357" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-2404 (MS15-065)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-2404" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2404" source="CVE"/>
        <description>Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-2385, CVE-2015-2390, CVE-2015-2397, CVE-2015-2406, and CVE-2015-2422.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-07-22T13:00:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-07-23T11:16:01.266-04:00">DRAFT</status_change>
            <status_change date="2015-08-10T04:00:51.680-04:00">INTERIM</status_change>
            <status_change date="2015-08-31T04:00:22.778-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5662" test_ref="oval:org.mitre.oval:tst:140298"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21481" test_ref="oval:org.mitre.oval:tst:140959"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista / 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19421" test_ref="oval:org.mitre.oval:tst:140954"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23728" test_ref="oval:org.mitre.oval:tst:141086"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23707" test_ref="oval:org.mitre.oval:tst:141287"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19652" test_ref="oval:org.mitre.oval:tst:141242"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23707" test_ref="oval:org.mitre.oval:tst:141287"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18896" test_ref="oval:org.mitre.oval:tst:141220"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.23099" test_ref="oval:org.mitre.oval:tst:141285"/>
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.23000" test_ref="oval:org.mitre.oval:tst:138202"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16669" test_ref="oval:org.mitre.oval:tst:141203"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20784" test_ref="oval:org.mitre.oval:tst:141111"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17412" test_ref="oval:org.mitre.oval:tst:140758"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21523" test_ref="oval:org.mitre.oval:tst:141225"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17905" test_ref="oval:org.mitre.oval:tst:141110"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29355" version="4" class="vulnerability">
      <metadata>
        <title>Internet Explorer ASLR bypass vulnerability - CVE-2015-2421 (MS15-065)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-2421" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2421" source="CVE"/>
        <description>Microsoft Internet Explorer 6 through 11 allows remote attackers to bypass the ASLR protection mechanism via a crafted web site, aka "Internet Explorer ASLR Bypass."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-07-22T13:00:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-07-23T11:16:05.529-04:00">DRAFT</status_change>
            <status_change date="2015-08-10T04:00:50.170-04:00">INTERIM</status_change>
            <status_change date="2015-08-31T04:00:22.294-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5662" test_ref="oval:org.mitre.oval:tst:140298"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21481" test_ref="oval:org.mitre.oval:tst:140959"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista / 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19421" test_ref="oval:org.mitre.oval:tst:140954"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23728" test_ref="oval:org.mitre.oval:tst:141086"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23707" test_ref="oval:org.mitre.oval:tst:141287"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19652" test_ref="oval:org.mitre.oval:tst:141242"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23707" test_ref="oval:org.mitre.oval:tst:141287"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18896" test_ref="oval:org.mitre.oval:tst:141220"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.23099" test_ref="oval:org.mitre.oval:tst:141285"/>
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.23000" test_ref="oval:org.mitre.oval:tst:138202"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16669" test_ref="oval:org.mitre.oval:tst:141203"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20784" test_ref="oval:org.mitre.oval:tst:141111"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17412" test_ref="oval:org.mitre.oval:tst:140758"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21523" test_ref="oval:org.mitre.oval:tst:141225"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17905" test_ref="oval:org.mitre.oval:tst:141110"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29332" version="3" class="vulnerability">
      <metadata>
        <title>ATMFD.DLL Memory corruption vulnerability - CVE-2015-2387 (MS15-077)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-2387" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2387"/>
        <description>ATMFD.DLL in the Adobe Type Manager Font Driver in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges via a crafted application, aka "ATMFD.DLL Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-07-22T13:00:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-07-23T11:32:13.105-04:00">DRAFT</status_change>
            <status_change date="2015-08-10T04:00:49.766-04:00">INTERIM</status_change>
            <status_change date="2015-08-31T04:00:21.996-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Server 2k3 and vulnerable file version">
          <criteria operator="OR" comment="2k3 (x86/x64/ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of atmfd.dll is less than 5.2.2.242" test_ref="oval:org.mitre.oval:tst:140421"/>
        </criteria>
        <criteria operator="AND" comment="Vista/2k8/Win7/2k8 R2/ Win 8/2k12/Win 8.1/2k12 R2 and vulnerable file version">
          <criteria operator="OR" comment="Vista/2k8/Win7/2k8 R2/ Win 8/2k12/Win 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of atmfd.dll is less than 5.1.2.242" test_ref="oval:org.mitre.oval:tst:141178"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29327" version="3" class="vulnerability">
      <metadata>
        <title>Windows RPC elevation of privilege vulnerability - CVE-2015-2370 (MS15-076)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Vista</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-2370" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2370"/>
        <description>The authentication implementation in the RPC subsystem in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 does not prevent DCE/RPC connection reflection, which allows local users to gain privileges via a crafted application, aka "Windows RPC Elevation of Privilege Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-07-22T13:00:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-07-23T11:30:38.407-04:00">DRAFT</status_change>
            <status_change date="2015-08-10T04:00:49.319-04:00">INTERIM</status_change>
            <status_change date="2015-08-31T04:00:21.714-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Server 2003 and vulnerable file version">
          <criteria operator="OR" comment="Server 2003 (x86/x64/ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of kerberos.dll is less than 5.2.3790.5669" test_ref="oval:org.mitre.oval:tst:141239"/>
        </criteria>
        <criteria operator="AND" comment="Vista/2k8(x86/x64/ia64) and vulnerable file version">
          <criteria operator="OR" comment="Vista/2k8(x86/x64/ia64)">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of Kerberos.dll is less than 6.0.6002.19431" test_ref="oval:org.mitre.oval:tst:141076"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of kerberos.dll is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:135821"/>
              <criterion comment="Check if the version of kerberos.dll is less than 6.0.6002.23737" test_ref="oval:org.mitre.oval:tst:140349"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / R2 (x86/x64/ia64) and vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of Kerberos.dll is less than 6.1.7601.18909" test_ref="oval:org.mitre.oval:tst:140560"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of kerberos.dll is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:135603"/>
              <criterion comment="Check if the version of kerberos.dll is less than 6.1.7601.23112" test_ref="oval:org.mitre.oval:tst:141041"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8/ Server 2012 (x86/x64/ia64) and vulnerable file version">
          <criteria operator="OR" comment="Win 8/ Server 2012 (x86/x64/ia64)">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of kerberos.dll is less than 6.2.9200.17420" test_ref="oval:org.mitre.oval:tst:140691"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of kerberos.dll is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:135794"/>
              <criterion comment="Check if the version of kerberos.dll is less than 6.2.9200.21529" test_ref="oval:org.mitre.oval:tst:141299"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1/2k12 R2 and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of kerberos.dll is less than 6.3.9600.17918" test_ref="oval:org.mitre.oval:tst:140736"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29324" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-2397 (MS15-065)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-2397" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2397" source="CVE"/>
        <description>Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-2385, CVE-2015-2390, CVE-2015-2404, CVE-2015-2406, and CVE-2015-2422.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-07-22T13:00:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-07-23T11:16:24.103-04:00">DRAFT</status_change>
            <status_change date="2015-08-10T04:00:48.951-04:00">INTERIM</status_change>
            <status_change date="2015-08-31T04:00:21.282-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5662" test_ref="oval:org.mitre.oval:tst:140298"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21481" test_ref="oval:org.mitre.oval:tst:140959"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista / 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19421" test_ref="oval:org.mitre.oval:tst:140954"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23728" test_ref="oval:org.mitre.oval:tst:141086"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23707" test_ref="oval:org.mitre.oval:tst:141287"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19652" test_ref="oval:org.mitre.oval:tst:141242"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23707" test_ref="oval:org.mitre.oval:tst:141287"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18896" test_ref="oval:org.mitre.oval:tst:141220"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.23099" test_ref="oval:org.mitre.oval:tst:141285"/>
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.23000" test_ref="oval:org.mitre.oval:tst:138202"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16669" test_ref="oval:org.mitre.oval:tst:141203"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20784" test_ref="oval:org.mitre.oval:tst:141111"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17412" test_ref="oval:org.mitre.oval:tst:140758"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21523" test_ref="oval:org.mitre.oval:tst:141225"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17905" test_ref="oval:org.mitre.oval:tst:141110"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29316" version="3" class="vulnerability">
      <metadata>
        <title>Jscript9 Memory corruption vulnerability - CVE-2015-2419 (MS15-065)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-2419" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2419" source="CVE"/>
        <description>JScript 9 in Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "JScript9 Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-07-22T13:00:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-07-23T11:16:21.268-04:00">DRAFT</status_change>
            <status_change date="2015-08-10T04:00:48.651-04:00">INTERIM</status_change>
            <status_change date="2015-08-31T04:00:20.872-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17412" test_ref="oval:org.mitre.oval:tst:140758"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21523" test_ref="oval:org.mitre.oval:tst:141225"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17905" test_ref="oval:org.mitre.oval:tst:141110"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29295" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-1729 (MS15-065)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-1729" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1729" source="CVE"/>
        <description>Microsoft Internet Explorer 9 through 11 allows remote attackers to read content from a different (1) domain or (2) zone via a crafted web site, aka "Internet Explorer Information Disclosure Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-07-22T13:00:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-07-23T11:16:17.942-04:00">DRAFT</status_change>
            <status_change date="2015-08-10T04:00:47.501-04:00">INTERIM</status_change>
            <status_change date="2015-08-31T04:00:19.599-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16669" test_ref="oval:org.mitre.oval:tst:141203"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20784" test_ref="oval:org.mitre.oval:tst:141111"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17412" test_ref="oval:org.mitre.oval:tst:140758"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21523" test_ref="oval:org.mitre.oval:tst:141225"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17905" test_ref="oval:org.mitre.oval:tst:141110"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29292" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-2408 (MS15-065)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-2408" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2408" source="CVE"/>
        <description>Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-1767 and CVE-2015-2401.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-07-22T13:00:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-07-23T11:16:02.935-04:00">DRAFT</status_change>
            <status_change date="2015-08-10T04:00:47.245-04:00">INTERIM</status_change>
            <status_change date="2015-08-31T04:00:19.108-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16669" test_ref="oval:org.mitre.oval:tst:141203"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20784" test_ref="oval:org.mitre.oval:tst:141111"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17412" test_ref="oval:org.mitre.oval:tst:140758"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21523" test_ref="oval:org.mitre.oval:tst:141225"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17905" test_ref="oval:org.mitre.oval:tst:141110"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29278" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-2385 (MS15-065)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-2385" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2385" source="CVE"/>
        <description>Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-2390, CVE-2015-2397, CVE-2015-2404, CVE-2015-2406, and CVE-2015-2422.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-07-22T13:00:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-07-23T11:16:38.192-04:00">DRAFT</status_change>
            <status_change date="2015-08-10T04:00:46.768-04:00">INTERIM</status_change>
            <status_change date="2015-08-31T04:00:18.296-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5662" test_ref="oval:org.mitre.oval:tst:140298"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21481" test_ref="oval:org.mitre.oval:tst:140959"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista / 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19421" test_ref="oval:org.mitre.oval:tst:140954"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23728" test_ref="oval:org.mitre.oval:tst:141086"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23707" test_ref="oval:org.mitre.oval:tst:141287"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19652" test_ref="oval:org.mitre.oval:tst:141242"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23707" test_ref="oval:org.mitre.oval:tst:141287"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18896" test_ref="oval:org.mitre.oval:tst:141220"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.23099" test_ref="oval:org.mitre.oval:tst:141285"/>
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.23000" test_ref="oval:org.mitre.oval:tst:138202"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16669" test_ref="oval:org.mitre.oval:tst:141203"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20784" test_ref="oval:org.mitre.oval:tst:141111"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17412" test_ref="oval:org.mitre.oval:tst:140758"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21523" test_ref="oval:org.mitre.oval:tst:141225"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17905" test_ref="oval:org.mitre.oval:tst:141110"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29219" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-2411 (MS15-065)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-2411" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2411" source="CVE"/>
        <description>Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-1733 and CVE-2015-2389.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-07-22T13:00:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-07-23T11:16:07.261-04:00">DRAFT</status_change>
            <status_change date="2015-08-10T04:00:46.027-04:00">INTERIM</status_change>
            <status_change date="2015-08-31T04:00:17.343-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17412" test_ref="oval:org.mitre.oval:tst:140758"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21523" test_ref="oval:org.mitre.oval:tst:141225"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17905" test_ref="oval:org.mitre.oval:tst:141110"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29198" version="3" class="vulnerability">
      <metadata>
        <title>OLE Elevation of privilege vulnerability - CVE-2015-2417 (MS15-075)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Vista</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-2417" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2417"/>
        <description>OLE in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to gain privileges via crafted input, as demonstrated by a transition from Low Integrity to Medium Integrity, aka "OLE Elevation of Privilege Vulnerability," a different vulnerability than CVE-2015-2416.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-07-22T12:06:54">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-07-23T11:29:09.429-04:00">DRAFT</status_change>
            <status_change date="2015-08-10T04:00:45.570-04:00">INTERIM</status_change>
            <status_change date="2015-08-31T04:00:16.708-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 2K3">
          <criteria operator="OR" comment="Check for vulnerable Microsoft Windows OS">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of Ole32.dll is less than 5.2.3790.5663" test_ref="oval:org.mitre.oval:tst:140974"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista SP2 x86/x64, Server 2008 SP2 32bit/x64/ia64">
          <criteria operator="OR" comment="Check for vulnerable Microsoft Windows OS">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="Check if the version of Ole32.dll is less than 6.0.6002.19435" test_ref="oval:org.mitre.oval:tst:140324"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="Check if the version of Ole32.dll is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:141237"/>
              <criterion comment="Check if the version of Ole32.dll is less than 6.0.6002.23743" test_ref="oval:org.mitre.oval:tst:140765"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 7 x86/x64, Server 2008 R2 x64/ia64">
          <criteria operator="OR" comment="Check for vulnerable Microsoft Windows OS">
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="Check if the version of Ole32.dll is less than 6.1.7601.18896" test_ref="oval:org.mitre.oval:tst:141296"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="Check if the version of Ole32.dll is greater than or equal to 6.1.7601.23000" test_ref="oval:org.mitre.oval:tst:141207"/>
              <criterion comment="Check if the version of Ole32.dll is less than 6.1.7601.23099" test_ref="oval:org.mitre.oval:tst:140818"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8 / 2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criteria operator="AND" comment="Check for LDR range">
              <criterion comment="Check if the version of Ole32.dll is less than 6.2.9200.21524" test_ref="oval:org.mitre.oval:tst:141136"/>
              <criterion comment="Check if the version of Ole32.dll is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:140969"/>
            </criteria>
            <criterion comment="Check if the version of Ole32.dll is less than 6.2.9200.17414" test_ref="oval:org.mitre.oval:tst:141309"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="8.1/2012 R2 and vulnerable version">
          <criteria operator="OR" comment="8.1/ 2012 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of Ole32.dll is less than 6.3.9600.17905" test_ref="oval:org.mitre.oval:tst:140986"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29159" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-2412 (MS15-065)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-2412" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2412" source="CVE"/>
        <description>Microsoft Internet Explorer 10 and 11 allows remote attackers to read arbitrary local files via a crafted pathname, aka "Internet Explorer Information Disclosure Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-07-22T13:00:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-07-23T11:16:15.003-04:00">DRAFT</status_change>
            <status_change date="2015-08-10T04:00:45.142-04:00">INTERIM</status_change>
            <status_change date="2015-08-31T04:00:16.132-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17412" test_ref="oval:org.mitre.oval:tst:140758"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21523" test_ref="oval:org.mitre.oval:tst:141225"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17905" test_ref="oval:org.mitre.oval:tst:141110"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29156" version="3" class="vulnerability">
      <metadata>
        <title>Win32k elevation of privilege vulnerability - CVE-2015-2365 (MS15-073)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-2365" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2365"/>
        <description>win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-07-22T16:53:08">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-07-23T11:25:49.098-04:00">DRAFT</status_change>
            <status_change date="2015-08-10T04:00:44.843-04:00">INTERIM</status_change>
            <status_change date="2015-08-31T04:00:15.662-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Windows Server 2k3 and vulnerable file version">
          <criteria operator="OR" comment="Either OS">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of win32k.sys is less than 5.2.3790.5667" test_ref="oval:org.mitre.oval:tst:141098"/>
        </criteria>
        <criteria operator="AND" comment="Vista / 2k8 + vulnerable file version">
          <criteria operator="OR" comment="Vista / 2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.0.6002.19429" test_ref="oval:org.mitre.oval:tst:141152"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:81723"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.0.6002.23735" test_ref="oval:org.mitre.oval:tst:141262"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / R2 + vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.18906" test_ref="oval:org.mitre.oval:tst:141244"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:81763"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.23109" test_ref="oval:org.mitre.oval:tst:141301"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8/2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.17419" test_ref="oval:org.mitre.oval:tst:141068"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:115678"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.21528" test_ref="oval:org.mitre.oval:tst:141153"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1 / 2K12 R2and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of win32k.sys is less than 6.3.9600.17915" test_ref="oval:org.mitre.oval:tst:141251"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29147" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer elevation of privilege vulnerability - CVE-2015-1743 (MS15-056)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-1743" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1743" source="CVE"/>
        <description>Microsoft Internet Explorer 7 through 11 allows remote attackers to gain privileges via a crafted web site, aka "Internet Explorer Elevation of Privilege Vulnerability," a different vulnerability than CVE-2015-1748.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-16T04:41:39">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-06-18T10:14:19.881-04:00">DRAFT</status_change>
            <status_change date="2015-07-06T04:00:45.948-04:00">INTERIM</status_change>
            <status_change date="2015-07-27T04:01:12.776-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21466" test_ref="oval:org.mitre.oval:tst:138892"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista / 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19383" test_ref="oval:org.mitre.oval:tst:138665"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23690" test_ref="oval:org.mitre.oval:tst:139050"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23687" test_ref="oval:org.mitre.oval:tst:138276"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19632" test_ref="oval:org.mitre.oval:tst:138942"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23687" test_ref="oval:org.mitre.oval:tst:138276"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18870" test_ref="oval:org.mitre.oval:tst:138751"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.23073" test_ref="oval:org.mitre.oval:tst:138584"/>
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.23000" test_ref="oval:org.mitre.oval:tst:138202"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16659" test_ref="oval:org.mitre.oval:tst:138475"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20774" test_ref="oval:org.mitre.oval:tst:138843"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17377" test_ref="oval:org.mitre.oval:tst:139004"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21489" test_ref="oval:org.mitre.oval:tst:138844"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17842" test_ref="oval:org.mitre.oval:tst:138937"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29145" version="3" class="vulnerability">
      <metadata>
        <title>Win32k Null pointer dereference vulnerability - CVE-2015-1721 (MS15-061)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-1721" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1721"/>
        <description>The kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allow local users to gain privileges or cause a denial of service (NULL pointer dereference and system crash) via a crafted application, aka "Win32k Null Pointer Dereference Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-16T10:41:46">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-06-18T10:24:15.663-04:00">DRAFT</status_change>
            <status_change date="2015-07-06T04:00:45.736-04:00">INTERIM</status_change>
            <status_change date="2015-07-27T04:01:12.347-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Windows Server 2k3 and vulnerable file version">
          <criteria operator="OR" comment="Either OS">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of win32k.sys is less than 5.2.3790.5640" test_ref="oval:org.mitre.oval:tst:138918"/>
        </criteria>
        <criteria operator="AND" comment="Vista / 2k8 + vulnerable file version">
          <criteria operator="OR" comment="Vista / 2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.0.6002.19399" test_ref="oval:org.mitre.oval:tst:138917"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:81723"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.0.6002.23706" test_ref="oval:org.mitre.oval:tst:139029"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / R2 + vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.18869" test_ref="oval:org.mitre.oval:tst:138921"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:81763"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.23072" test_ref="oval:org.mitre.oval:tst:138932"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8/2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.17385" test_ref="oval:org.mitre.oval:tst:138372"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:115678"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.21496" test_ref="oval:org.mitre.oval:tst:138968"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1 / 2K12 R2and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of win32k.sys is less than 6.3.9600.17837" test_ref="oval:org.mitre.oval:tst:139008"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29142" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer elevation of privilege vulnerability - CVE-2015-1739 (MS15-056)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-1739" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1739" source="CVE"/>
        <description>Microsoft Internet Explorer 10 and 11 allows remote attackers to gain privileges via a crafted web site, aka "Internet Explorer Elevation of Privilege Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-16T04:41:39">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-06-18T10:14:42.416-04:00">DRAFT</status_change>
            <status_change date="2015-07-06T04:00:45.092-04:00">INTERIM</status_change>
            <status_change date="2015-07-27T04:01:11.676-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17377" test_ref="oval:org.mitre.oval:tst:139004"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21489" test_ref="oval:org.mitre.oval:tst:138844"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17842" test_ref="oval:org.mitre.oval:tst:138937"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29132" version="3" class="vulnerability">
      <metadata>
        <title>Win32k information disclosure vulnerability - CVE-2015-2382 (MS15-073)</title>
        <affected family="windows">
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-2382" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2382"/>
        <description>win32k.sys in the kernel-mode drivers in Microsoft Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to obtain sensitive information from kernel memory via a crafted application, aka "Win32k Information Disclosure Vulnerability," a different vulnerability than CVE-2015-2381.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-07-22T16:53:08">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-07-23T11:25:51.869-04:00">DRAFT</status_change>
            <status_change date="2015-08-10T04:00:44.059-04:00">INTERIM</status_change>
            <status_change date="2015-08-31T04:00:14.938-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Win 8/2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.17419" test_ref="oval:org.mitre.oval:tst:141068"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:115678"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.21528" test_ref="oval:org.mitre.oval:tst:141153"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1 / 2K12 R2and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of win32k.sys is less than 6.3.9600.17915" test_ref="oval:org.mitre.oval:tst:141251"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29128" version="3" class="vulnerability">
      <metadata>
        <title>Win32k elevation of privilege vulnerability - CVE-2015-2366 (MS15-073)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-2366" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2366"/>
        <description>win32k.sys in the kernel-mode drivers in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-07-22T16:53:08">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-07-23T11:25:55.121-04:00">DRAFT</status_change>
            <status_change date="2015-08-10T04:00:43.840-04:00">INTERIM</status_change>
            <status_change date="2015-08-31T04:00:14.665-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Win 7 / R2 + vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.18906" test_ref="oval:org.mitre.oval:tst:141244"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:81763"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.23109" test_ref="oval:org.mitre.oval:tst:141301"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8/2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.17419" test_ref="oval:org.mitre.oval:tst:141068"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:115678"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.21528" test_ref="oval:org.mitre.oval:tst:141153"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1 / 2K12 R2and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of win32k.sys is less than 6.3.9600.17915" test_ref="oval:org.mitre.oval:tst:141251"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29124" version="3" class="vulnerability">
      <metadata>
        <title>Microsoft Windows Kernel Object use after free vulnerability - CVE-2015-1724 (MS15-061)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-1724" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1724"/>
        <description>Use-after-free vulnerability in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges via a crafted application, aka "Microsoft Windows Kernel Object Use After Free Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-16T10:41:46">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-06-18T10:24:31.348-04:00">DRAFT</status_change>
            <status_change date="2015-07-06T04:00:44.463-04:00">INTERIM</status_change>
            <status_change date="2015-07-27T04:01:08.671-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Windows Server 2k3 and vulnerable file version">
          <criteria operator="OR" comment="Either OS">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of win32k.sys is less than 5.2.3790.5640" test_ref="oval:org.mitre.oval:tst:138918"/>
        </criteria>
        <criteria operator="AND" comment="Vista / 2k8 + vulnerable file version">
          <criteria operator="OR" comment="Vista / 2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.0.6002.19399" test_ref="oval:org.mitre.oval:tst:138917"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:81723"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.0.6002.23706" test_ref="oval:org.mitre.oval:tst:139029"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / R2 + vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.18869" test_ref="oval:org.mitre.oval:tst:138921"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:81763"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.23072" test_ref="oval:org.mitre.oval:tst:138932"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8/2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.17385" test_ref="oval:org.mitre.oval:tst:138372"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:115678"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.21496" test_ref="oval:org.mitre.oval:tst:138968"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1 / 2K12 R2and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of win32k.sys is less than 6.3.9600.17837" test_ref="oval:org.mitre.oval:tst:139008"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29123" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-1740 (MS15-056)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-1740" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1740" source="CVE"/>
        <description>Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-1735, CVE-2015-1744, CVE-2015-1745, and CVE-2015-1766.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-16T04:41:39">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-06-18T10:14:36.047-04:00">DRAFT</status_change>
            <status_change date="2015-07-06T04:00:44.166-04:00">INTERIM</status_change>
            <status_change date="2015-07-27T04:01:08.222-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5624" test_ref="oval:org.mitre.oval:tst:138803"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21466" test_ref="oval:org.mitre.oval:tst:138892"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista / 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19383" test_ref="oval:org.mitre.oval:tst:138665"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23690" test_ref="oval:org.mitre.oval:tst:139050"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23687" test_ref="oval:org.mitre.oval:tst:138276"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19632" test_ref="oval:org.mitre.oval:tst:138942"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23687" test_ref="oval:org.mitre.oval:tst:138276"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18870" test_ref="oval:org.mitre.oval:tst:138751"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.23073" test_ref="oval:org.mitre.oval:tst:138584"/>
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.23000" test_ref="oval:org.mitre.oval:tst:138202"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16659" test_ref="oval:org.mitre.oval:tst:138475"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20774" test_ref="oval:org.mitre.oval:tst:138843"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17377" test_ref="oval:org.mitre.oval:tst:139004"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21489" test_ref="oval:org.mitre.oval:tst:138844"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17842" test_ref="oval:org.mitre.oval:tst:138937"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29118" version="3" class="vulnerability">
      <metadata>
        <title>Microsoft Windows Kernel use after free vulnerability – CVE-2015-1720 (MS15-061)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-1720" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1720"/>
        <description>Use-after-free vulnerability in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges via a crafted application, aka "Microsoft Windows Kernel Use After Free Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-16T10:41:46">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-06-18T10:24:13.516-04:00">DRAFT</status_change>
            <status_change date="2015-07-06T04:00:43.770-04:00">INTERIM</status_change>
            <status_change date="2015-07-27T04:01:07.692-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Windows Server 2k3 and vulnerable file version">
          <criteria operator="OR" comment="Either OS">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of win32k.sys is less than 5.2.3790.5640" test_ref="oval:org.mitre.oval:tst:138918"/>
        </criteria>
        <criteria operator="AND" comment="Vista / 2k8 + vulnerable file version">
          <criteria operator="OR" comment="Vista / 2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.0.6002.19399" test_ref="oval:org.mitre.oval:tst:138917"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:81723"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.0.6002.23706" test_ref="oval:org.mitre.oval:tst:139029"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / R2 + vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.18869" test_ref="oval:org.mitre.oval:tst:138921"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:81763"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.23072" test_ref="oval:org.mitre.oval:tst:138932"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8/2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.17385" test_ref="oval:org.mitre.oval:tst:138372"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:115678"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.21496" test_ref="oval:org.mitre.oval:tst:138968"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1 / 2K12 R2and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of win32k.sys is less than 6.3.9600.17837" test_ref="oval:org.mitre.oval:tst:139008"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29113" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-1735 (MS15-056)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-1735" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1735" source="CVE"/>
        <description>Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-1740, CVE-2015-1744, CVE-2015-1745, and CVE-2015-1766.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-16T04:41:39">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-06-18T10:14:32.864-04:00">DRAFT</status_change>
            <status_change date="2015-07-06T04:00:43.444-04:00">INTERIM</status_change>
            <status_change date="2015-07-27T04:01:06.735-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5624" test_ref="oval:org.mitre.oval:tst:138803"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21466" test_ref="oval:org.mitre.oval:tst:138892"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista / 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19383" test_ref="oval:org.mitre.oval:tst:138665"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23690" test_ref="oval:org.mitre.oval:tst:139050"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23687" test_ref="oval:org.mitre.oval:tst:138276"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19632" test_ref="oval:org.mitre.oval:tst:138942"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23687" test_ref="oval:org.mitre.oval:tst:138276"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18870" test_ref="oval:org.mitre.oval:tst:138751"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.23073" test_ref="oval:org.mitre.oval:tst:138584"/>
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.23000" test_ref="oval:org.mitre.oval:tst:138202"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16659" test_ref="oval:org.mitre.oval:tst:138475"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20774" test_ref="oval:org.mitre.oval:tst:138843"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17377" test_ref="oval:org.mitre.oval:tst:139004"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21489" test_ref="oval:org.mitre.oval:tst:138844"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17842" test_ref="oval:org.mitre.oval:tst:138937"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29093" version="3" class="vulnerability">
      <metadata>
        <title>Microsoft Windows Kernel information disclosure vulnerability – CVE-2015-1719 (MS15-061)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-1719" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1719"/>
        <description>The kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allow local users to obtain sensitive information from kernel memory via a crafted application, aka "Microsoft Windows Kernel Information Disclosure Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-16T10:41:46">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-06-18T10:24:33.625-04:00">DRAFT</status_change>
            <status_change date="2015-07-06T04:00:42.325-04:00">INTERIM</status_change>
            <status_change date="2015-07-27T04:01:03.465-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Windows Server 2k3 and vulnerable file version">
          <criteria operator="OR" comment="Either OS">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of win32k.sys is less than 5.2.3790.5640" test_ref="oval:org.mitre.oval:tst:138918"/>
        </criteria>
        <criteria operator="AND" comment="Vista / 2k8 + vulnerable file version">
          <criteria operator="OR" comment="Vista / 2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.0.6002.19399" test_ref="oval:org.mitre.oval:tst:138917"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:81723"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.0.6002.23706" test_ref="oval:org.mitre.oval:tst:139029"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / R2 + vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.18869" test_ref="oval:org.mitre.oval:tst:138921"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:81763"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.23072" test_ref="oval:org.mitre.oval:tst:138932"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8/2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.17385" test_ref="oval:org.mitre.oval:tst:138372"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:115678"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.21496" test_ref="oval:org.mitre.oval:tst:138968"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1 / 2K12 R2and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of win32k.sys is less than 6.3.9600.17837" test_ref="oval:org.mitre.oval:tst:139008"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29087" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-2410 (MS15-065)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-2410" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2410" source="CVE"/>
        <description>Microsoft Internet Explorer 6 through 11 allows remote attackers to determine the existence of local files via a crafted stylesheet, aka "Internet Explorer Information Disclosure Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-07-22T13:00:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-07-23T11:16:46.838-04:00">DRAFT</status_change>
            <status_change date="2015-08-10T04:00:43.376-04:00">INTERIM</status_change>
            <status_change date="2015-08-31T04:00:14.068-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5662" test_ref="oval:org.mitre.oval:tst:140298"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21481" test_ref="oval:org.mitre.oval:tst:140959"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista / 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19421" test_ref="oval:org.mitre.oval:tst:140954"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23728" test_ref="oval:org.mitre.oval:tst:141086"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23707" test_ref="oval:org.mitre.oval:tst:141287"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19652" test_ref="oval:org.mitre.oval:tst:141242"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23707" test_ref="oval:org.mitre.oval:tst:141287"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18896" test_ref="oval:org.mitre.oval:tst:141220"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.23099" test_ref="oval:org.mitre.oval:tst:141285"/>
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.23000" test_ref="oval:org.mitre.oval:tst:138202"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16669" test_ref="oval:org.mitre.oval:tst:141203"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20784" test_ref="oval:org.mitre.oval:tst:141111"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17412" test_ref="oval:org.mitre.oval:tst:140758"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21523" test_ref="oval:org.mitre.oval:tst:141225"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17905" test_ref="oval:org.mitre.oval:tst:141110"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29076" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-1766 (MS15-056)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-1766" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1766" source="CVE"/>
        <description>Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-1735, CVE-2015-1740, CVE-2015-1744, and CVE-2015-1745.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-16T04:41:39">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-06-18T10:14:13.617-04:00">DRAFT</status_change>
            <status_change date="2015-07-06T04:00:40.866-04:00">INTERIM</status_change>
            <status_change date="2015-07-27T04:01:00.297-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5624" test_ref="oval:org.mitre.oval:tst:138803"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21466" test_ref="oval:org.mitre.oval:tst:138892"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista / 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19383" test_ref="oval:org.mitre.oval:tst:138665"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23690" test_ref="oval:org.mitre.oval:tst:139050"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23687" test_ref="oval:org.mitre.oval:tst:138276"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19632" test_ref="oval:org.mitre.oval:tst:138942"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23687" test_ref="oval:org.mitre.oval:tst:138276"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18870" test_ref="oval:org.mitre.oval:tst:138751"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.23073" test_ref="oval:org.mitre.oval:tst:138584"/>
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.23000" test_ref="oval:org.mitre.oval:tst:138202"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16659" test_ref="oval:org.mitre.oval:tst:138475"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20774" test_ref="oval:org.mitre.oval:tst:138843"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17377" test_ref="oval:org.mitre.oval:tst:139004"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21489" test_ref="oval:org.mitre.oval:tst:138844"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17842" test_ref="oval:org.mitre.oval:tst:138937"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29075" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer XSS filter bypass vulnerability - CVE-2015-2398 (MS15-065)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-2398" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2398" source="CVE"/>
        <description>Microsoft Internet Explorer 8 through 11 allows remote attackers to bypass the XSS filter via a crafted attribute of an element in an HTML document, aka "Internet Explorer XSS Filter Bypass Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-07-22T13:00:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-07-23T11:16:44.325-04:00">DRAFT</status_change>
            <status_change date="2015-08-10T04:00:43.058-04:00">INTERIM</status_change>
            <status_change date="2015-08-31T04:00:13.558-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23707" test_ref="oval:org.mitre.oval:tst:141287"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19652" test_ref="oval:org.mitre.oval:tst:141242"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23707" test_ref="oval:org.mitre.oval:tst:141287"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18896" test_ref="oval:org.mitre.oval:tst:141220"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.23099" test_ref="oval:org.mitre.oval:tst:141285"/>
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.23000" test_ref="oval:org.mitre.oval:tst:138202"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16669" test_ref="oval:org.mitre.oval:tst:141203"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20784" test_ref="oval:org.mitre.oval:tst:141111"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17412" test_ref="oval:org.mitre.oval:tst:140758"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21523" test_ref="oval:org.mitre.oval:tst:141225"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17905" test_ref="oval:org.mitre.oval:tst:141110"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29067" version="3" class="vulnerability">
      <metadata>
        <title>Microsoft Windows Station use after free vulnerability - CVE-2015-1723 (MS15-061)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-1723" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1723"/>
        <description>Use-after-free vulnerability in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges via a crafted application, aka "Microsoft Windows Station Use After Free Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-16T10:41:46">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-06-18T10:24:17.588-04:00">DRAFT</status_change>
            <status_change date="2015-07-06T04:00:39.183-04:00">INTERIM</status_change>
            <status_change date="2015-07-27T04:00:57.483-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Windows Server 2k3 and vulnerable file version">
          <criteria operator="OR" comment="Either OS">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of win32k.sys is less than 5.2.3790.5640" test_ref="oval:org.mitre.oval:tst:138918"/>
        </criteria>
        <criteria operator="AND" comment="Vista / 2k8 + vulnerable file version">
          <criteria operator="OR" comment="Vista / 2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.0.6002.19399" test_ref="oval:org.mitre.oval:tst:138917"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:81723"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.0.6002.23706" test_ref="oval:org.mitre.oval:tst:139029"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / R2 + vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.18869" test_ref="oval:org.mitre.oval:tst:138921"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:81763"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.23072" test_ref="oval:org.mitre.oval:tst:138932"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8/2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.17385" test_ref="oval:org.mitre.oval:tst:138372"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:115678"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.21496" test_ref="oval:org.mitre.oval:tst:138968"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1 / 2K12 R2and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of win32k.sys is less than 6.3.9600.17837" test_ref="oval:org.mitre.oval:tst:139008"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29060" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-1751 (MS15-056)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <product>Microsoft Internet Explorer 10</product>
        </affected>
        <reference ref_id="CVE-2015-1751" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1751" source="CVE"/>
        <description>Microsoft Internet Explorer 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-16T04:41:39">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-06-18T10:14:03.315-04:00">DRAFT</status_change>
            <status_change date="2015-07-06T04:00:38.875-04:00">INTERIM</status_change>
            <status_change date="2015-07-27T04:00:56.937-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
        <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
          <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
          <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
          <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
          <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
          <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
        </criteria>
        <criteria operator="OR" comment="Check for vulnerable versions">
          <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17377" test_ref="oval:org.mitre.oval:tst:139004"/>
          <criteria operator="AND" comment="Check for LDR">
            <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21489" test_ref="oval:org.mitre.oval:tst:138844"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29050" version="3" class="vulnerability">
      <metadata>
        <title>Win32k Pool buffer overflow vulnerability - CVE-2015-1727 (MS15-061)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-1727" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1727"/>
        <description>Buffer overflow in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges via a crafted application, aka "Win32k Pool Buffer Overflow Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-16T10:41:46">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-06-18T10:24:26.307-04:00">DRAFT</status_change>
            <status_change date="2015-07-06T04:00:38.464-04:00">INTERIM</status_change>
            <status_change date="2015-07-27T04:00:56.042-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Windows Server 2k3 and vulnerable file version">
          <criteria operator="OR" comment="Either OS">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of win32k.sys is less than 5.2.3790.5640" test_ref="oval:org.mitre.oval:tst:138918"/>
        </criteria>
        <criteria operator="AND" comment="Vista / 2k8 + vulnerable file version">
          <criteria operator="OR" comment="Vista / 2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.0.6002.19399" test_ref="oval:org.mitre.oval:tst:138917"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:81723"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.0.6002.23706" test_ref="oval:org.mitre.oval:tst:139029"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / R2 + vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.18869" test_ref="oval:org.mitre.oval:tst:138921"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:81763"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.23072" test_ref="oval:org.mitre.oval:tst:138932"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8/2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.17385" test_ref="oval:org.mitre.oval:tst:138372"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:115678"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.21496" test_ref="oval:org.mitre.oval:tst:138968"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1 / 2K12 R2and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of win32k.sys is less than 6.3.9600.17837" test_ref="oval:org.mitre.oval:tst:139008"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29016" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer ASLR bypass vulnerability - CVE-2015-1685 (MS15-043)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-1685" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1685" source="CVE"/>
        <description>Microsoft Internet Explorer 11 allows remote attackers to bypass the ASLR protection mechanism via a crafted web site, aka "Internet Explorer ASLR Bypass."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-05-20T08:43:05">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-05-28T14:16:12.160-04:00">DRAFT</status_change>
            <status_change date="2015-06-15T04:00:32.856-04:00">INTERIM</status_change>
            <status_change date="2015-07-06T04:00:37.568-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
        <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
          <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
          <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
          <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
          <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
          <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
        </criteria>
        <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17801" test_ref="oval:org.mitre.oval:tst:138184"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29015" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-1767 (MS15-065)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-1767" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1767" source="CVE"/>
        <description>Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-2401 and CVE-2015-2408.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-07-22T13:00:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-07-23T11:16:33.802-04:00">DRAFT</status_change>
            <status_change date="2015-08-10T04:00:42.386-04:00">INTERIM</status_change>
            <status_change date="2015-08-31T04:00:12.929-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16669" test_ref="oval:org.mitre.oval:tst:141203"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20784" test_ref="oval:org.mitre.oval:tst:141111"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17412" test_ref="oval:org.mitre.oval:tst:140758"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21523" test_ref="oval:org.mitre.oval:tst:141225"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17905" test_ref="oval:org.mitre.oval:tst:141110"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29005" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer elevation of privilege vulnerability - CVE-2015-1748 (MS15-056)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-1748" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1748" source="CVE"/>
        <description>Microsoft Internet Explorer 7 through 11 allows remote attackers to gain privileges via a crafted web site, aka "Internet Explorer Elevation of Privilege Vulnerability," a different vulnerability than CVE-2015-1743.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-16T04:41:39">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-06-18T10:14:16.086-04:00">DRAFT</status_change>
            <status_change date="2015-07-06T04:00:37.151-04:00">INTERIM</status_change>
            <status_change date="2015-07-27T04:00:49.587-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21466" test_ref="oval:org.mitre.oval:tst:138892"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista / 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19383" test_ref="oval:org.mitre.oval:tst:138665"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23690" test_ref="oval:org.mitre.oval:tst:139050"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23687" test_ref="oval:org.mitre.oval:tst:138276"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19632" test_ref="oval:org.mitre.oval:tst:138942"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23687" test_ref="oval:org.mitre.oval:tst:138276"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18870" test_ref="oval:org.mitre.oval:tst:138751"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.23073" test_ref="oval:org.mitre.oval:tst:138584"/>
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.23000" test_ref="oval:org.mitre.oval:tst:138202"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16659" test_ref="oval:org.mitre.oval:tst:138475"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20774" test_ref="oval:org.mitre.oval:tst:138843"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17377" test_ref="oval:org.mitre.oval:tst:139004"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21489" test_ref="oval:org.mitre.oval:tst:138844"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17842" test_ref="oval:org.mitre.oval:tst:138937"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29001" version="3" class="vulnerability">
      <metadata>
        <title>Microsoft windows kernel memory disclosure vulnerability - CVE-2015-1676 (MS15-051)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-1676" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1676"/>
        <description>The kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allow local users to bypass the ASLR protection mechanism via a crafted function call, aka "Microsoft Windows Kernel Memory Disclosure Vulnerability," a different vulnerability than CVE-2015-1677, CVE-2015-1678, CVE-2015-1679, and CVE-2015-1680.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-05-20T18:56:32">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-05-28T14:30:23.410-04:00">DRAFT</status_change>
            <status_change date="2015-06-15T04:00:32.607-04:00">INTERIM</status_change>
            <status_change date="2015-07-06T04:00:36.852-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Windows Server 2k3 and vulnerable file version">
          <criteria operator="OR" comment="Either OS">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of win32k.sys is less than 5.2.3790.5615" test_ref="oval:org.mitre.oval:tst:138664"/>
        </criteria>
        <criteria operator="AND" comment="Vista / 2k8 + vulnerable file version">
          <criteria operator="OR" comment="Vista / 2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:81723"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.0.6002.23680" test_ref="oval:org.mitre.oval:tst:138658"/>
            </criteria>
            <criterion comment="Check if the version of win32k.sys is less than 6.0.6002.19372" test_ref="oval:org.mitre.oval:tst:138686"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / R2 + vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.1.7601.23000" test_ref="oval:org.mitre.oval:tst:138862"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.23038" test_ref="oval:org.mitre.oval:tst:138649"/>
            </criteria>
            <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.18834" test_ref="oval:org.mitre.oval:tst:138724"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8/2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:115678"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.21457" test_ref="oval:org.mitre.oval:tst:138582"/>
            </criteria>
            <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.17343" test_ref="oval:org.mitre.oval:tst:138343"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1 / 2K12 R2and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of win32k.sys is less than 6.3.9600.17796" test_ref="oval:org.mitre.oval:tst:138198"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29000" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-1658 (MS15-043)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-1658" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1658" source="CVE"/>
        <description>Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-1706, CVE-2015-1711, CVE-2015-1717, and CVE-2015-1718.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-05-20T08:43:05">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-05-28T14:16:28.786-04:00">DRAFT</status_change>
            <status_change date="2015-06-15T04:00:32.446-04:00">INTERIM</status_change>
            <status_change date="2015-07-06T04:00:36.619-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
        <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
          <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
          <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
          <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
          <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
          <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
        </criteria>
        <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17801" test_ref="oval:org.mitre.oval:tst:138184"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28994" version="3" class="vulnerability">
      <metadata>
        <title>Win32k elevation of privilege vulnerability - CVE-2015-2360 (MS15-061)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-2360" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2360"/>
        <description>win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges or cause a denial of service (memory corruption) via a crafted application, aka "Win32k Elevation of Privilege Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-16T10:41:46">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-06-18T10:24:21.750-04:00">DRAFT</status_change>
            <status_change date="2015-07-06T04:00:36.298-04:00">INTERIM</status_change>
            <status_change date="2015-07-27T04:00:49.298-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Windows Server 2k3 and vulnerable file version">
          <criteria operator="OR" comment="Either OS">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of win32k.sys is less than 5.2.3790.5640" test_ref="oval:org.mitre.oval:tst:138918"/>
        </criteria>
        <criteria operator="AND" comment="Vista / 2k8 + vulnerable file version">
          <criteria operator="OR" comment="Vista / 2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.0.6002.19399" test_ref="oval:org.mitre.oval:tst:138917"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:81723"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.0.6002.23706" test_ref="oval:org.mitre.oval:tst:139029"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / R2 + vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.18869" test_ref="oval:org.mitre.oval:tst:138921"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:81763"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.23072" test_ref="oval:org.mitre.oval:tst:138932"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8/2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.17385" test_ref="oval:org.mitre.oval:tst:138372"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:115678"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.21496" test_ref="oval:org.mitre.oval:tst:138968"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1 / 2K12 R2and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of win32k.sys is less than 6.3.9600.17837" test_ref="oval:org.mitre.oval:tst:139008"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28993" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-1717 (MS15-043)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-1717" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1717" source="CVE"/>
        <description>Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-1658, CVE-2015-1706, CVE-2015-1711, and CVE-2015-1718.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-05-20T08:43:05">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-05-28T14:16:15.134-04:00">DRAFT</status_change>
            <status_change date="2015-06-15T04:00:32.271-04:00">INTERIM</status_change>
            <status_change date="2015-07-06T04:00:36.134-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
        <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
          <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
          <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
          <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
          <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
          <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
        </criteria>
        <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17801" test_ref="oval:org.mitre.oval:tst:138184"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28990" version="3" class="vulnerability">
      <metadata>
        <title>OLE Elevation of privilege vulnerability - CVE-2015-2416 (MS15-075)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Vista</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-2416" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2416"/>
        <description>OLE in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to gain privileges via crafted input, as demonstrated by a transition from Low Integrity to Medium Integrity, aka "OLE Elevation of Privilege Vulnerability," a different vulnerability than CVE-2015-2417.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-07-22T12:06:54">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-07-23T11:29:07.182-04:00">DRAFT</status_change>
            <status_change date="2015-08-10T04:00:41.628-04:00">INTERIM</status_change>
            <status_change date="2015-08-31T04:00:12.043-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 2K3">
          <criteria operator="OR" comment="Check for vulnerable Microsoft Windows OS">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of Ole32.dll is less than 5.2.3790.5663" test_ref="oval:org.mitre.oval:tst:140974"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista SP2 x86/x64, Server 2008 SP2 32bit/x64/ia64">
          <criteria operator="OR" comment="Check for vulnerable Microsoft Windows OS">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="Check if the version of Ole32.dll is less than 6.0.6002.19435" test_ref="oval:org.mitre.oval:tst:140324"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="Check if the version of Ole32.dll is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:141237"/>
              <criterion comment="Check if the version of Ole32.dll is less than 6.0.6002.23743" test_ref="oval:org.mitre.oval:tst:140765"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 7 x86/x64, Server 2008 R2 x64/ia64">
          <criteria operator="OR" comment="Check for vulnerable Microsoft Windows OS">
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="Check if the version of Ole32.dll is less than 6.1.7601.18896" test_ref="oval:org.mitre.oval:tst:141296"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="Check if the version of Ole32.dll is greater than or equal to 6.1.7601.23000" test_ref="oval:org.mitre.oval:tst:141207"/>
              <criterion comment="Check if the version of Ole32.dll is less than 6.1.7601.23099" test_ref="oval:org.mitre.oval:tst:140818"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8 / 2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criteria operator="AND" comment="Check for LDR range">
              <criterion comment="Check if the version of Ole32.dll is less than 6.2.9200.21524" test_ref="oval:org.mitre.oval:tst:141136"/>
              <criterion comment="Check if the version of Ole32.dll is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:140969"/>
            </criteria>
            <criterion comment="Check if the version of Ole32.dll is less than 6.2.9200.17414" test_ref="oval:org.mitre.oval:tst:141309"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="8.1/2012 R2 and vulnerable version">
          <criteria operator="OR" comment="8.1/ 2012 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of Ole32.dll is less than 6.3.9600.17905" test_ref="oval:org.mitre.oval:tst:140986"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28984" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-1709 (MS15-043)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-1709" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1709" source="CVE"/>
        <description>Microsoft Internet Explorer 7 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-05-20T08:43:05">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-05-28T14:16:22.678-04:00">DRAFT</status_change>
            <status_change date="2015-06-15T04:00:31.731-04:00">INTERIM</status_change>
            <status_change date="2015-07-06T04:00:35.678-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23676" test_ref="oval:org.mitre.oval:tst:138485"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19621" test_ref="oval:org.mitre.oval:tst:138412"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23676" test_ref="oval:org.mitre.oval:tst:138485"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18835" test_ref="oval:org.mitre.oval:tst:138592"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.23038" test_ref="oval:org.mitre.oval:tst:137853"/>
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.23000" test_ref="oval:org.mitre.oval:tst:138202"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16644" test_ref="oval:org.mitre.oval:tst:138514"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20758" test_ref="oval:org.mitre.oval:tst:138561"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17357" test_ref="oval:org.mitre.oval:tst:138213"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21470" test_ref="oval:org.mitre.oval:tst:138585"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17801" test_ref="oval:org.mitre.oval:tst:138184"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28951" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-1705 (MS15-043)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-1705" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1705" source="CVE"/>
        <description>Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-1689.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-05-20T08:43:05">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-05-28T14:16:24.391-04:00">DRAFT</status_change>
            <status_change date="2015-06-15T04:00:31.424-04:00">INTERIM</status_change>
            <status_change date="2015-07-06T04:00:35.237-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16644" test_ref="oval:org.mitre.oval:tst:138514"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20758" test_ref="oval:org.mitre.oval:tst:138561"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17357" test_ref="oval:org.mitre.oval:tst:138213"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21470" test_ref="oval:org.mitre.oval:tst:138585"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17801" test_ref="oval:org.mitre.oval:tst:138184"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28950" version="4" class="vulnerability">
      <metadata>
        <title>Windows forms elevation of privilege vulnerability - CVE-2015-1673 (MS15-048)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows Vista</platform>
          <product>Microsoft .NET Framework 1.1</product>
          <product>Microsoft .NET Framework 2.0</product>
          <product>Microsoft .NET Framework 3.5</product>
          <product>Microsoft .NET Framework 3.5.1</product>
          <product>Microsoft .NET Framework 4.0</product>
          <product>Microsoft .NET Framework 4.5</product>
          <product>Microsoft .NET Framework 4.5.1</product>
          <product>Microsoft .NET Framework 4.5.2</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-1673" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1673"/>
        <description>The Windows Forms (aka WinForms) libraries in Microsoft .NET Framework 1.1 SP1, 2.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, and 4.5.2 allow user-assisted remote attackers to execute arbitrary code via a crafted partial-trust application, aka "Windows Forms Elevation of Privilege Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-05-20T11:54:36">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-05-28T14:34:59.080-04:00">DRAFT</status_change>
            <status_change date="2015-06-15T04:00:31.089-04:00">INTERIM</status_change>
            <status_change date="2015-07-06T04:00:34.795-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:28950 - Changed product names to represent versions consistently." date="2015-08-17T14:52:00.686-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-08-17T14:55:16.687-04:00">INTERIM</status_change>
          </dates>
          <status>INTERIM</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment=".NET 1.1 and vulnerable file">
          <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
          <extend_definition comment="Microsoft .NET Framework 1.1 Service Pack 1 is Installed" definition_ref="oval:org.mitre.oval:def:1834"/>
          <criterion comment="Check if the version of mscorlib.dll is less than 1.1.4322.2512" test_ref="oval:org.mitre.oval:tst:138654"/>
        </criteria>
        <criteria operator="AND" comment=".NET 2.0 and  XP / server 2003">
          <criteria operator="OR" comment="Either OS">
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 2.0 Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6158"/>
          <criteria operator="OR" comment="gdr and ldr range">
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of System.Windows.Forms.dll is less than 2.0.50727.8655" test_ref="oval:org.mitre.oval:tst:138616"/>
              <criterion comment="Check if the version of System.Windows.Forms.dll is greater than or equal to 2.0.50727.8600" test_ref="oval:org.mitre.oval:tst:138704"/>
            </criteria>
            <criterion comment="Check if the version of System.Windows.Forms.dll is less than 2.0.50727.3667" test_ref="oval:org.mitre.oval:tst:138084"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment=".NET 2.0 and Vista / 2008">
          <criteria operator="OR" comment="Either OS">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 2.0 Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6158"/>
          <criteria operator="OR" comment="gdr and ldr range">
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of System.Windows.Forms.dll is less than 2.0.50727.8653" test_ref="oval:org.mitre.oval:tst:138136"/>
              <criterion comment="Check if the version of System.Windows.Forms.dll is greater than or equal to 2.0.50727.8600" test_ref="oval:org.mitre.oval:tst:138704"/>
            </criteria>
            <criterion comment="Check if the version of System.Windows.Forms.dll is less than 2.0.50727.4257" test_ref="oval:org.mitre.oval:tst:138542"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment=".NET 3.5 and Win 8 / server 2012">
          <criteria operator="OR" comment="Either OS">
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 3.5 SP1 is installed" definition_ref="oval:org.mitre.oval:def:12542"/>
          <criteria operator="OR" comment="gdr and ldr range">
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of System.Windows.Forms.dll is less than 2.0.50727.8653" test_ref="oval:org.mitre.oval:tst:138136"/>
              <criterion comment="Check if the version of System.Windows.Forms.dll is greater than or equal to 2.0.50727.8600" test_ref="oval:org.mitre.oval:tst:138704"/>
            </criteria>
            <criterion comment="Check if the version of System.Windows.Forms.dll is less than 2.0.50727.6427" test_ref="oval:org.mitre.oval:tst:138639"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment=".NET and Win 8.1 / 2012 R2">
          <criteria operator="OR" comment="Either OS">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 3.5 SP1 is installed" definition_ref="oval:org.mitre.oval:def:12542"/>
          <criteria operator="OR" comment="gdr and ldr range">
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of System.Windows.Forms.dll is less than 2.0.50727.8653" test_ref="oval:org.mitre.oval:tst:138136"/>
              <criterion comment="Check if the version of System.Windows.Forms.dll is greater than or equal to 2.0.50727.8600" test_ref="oval:org.mitre.oval:tst:138704"/>
            </criteria>
            <criterion comment="Check if the version of System.Windows.Forms.dll is less than 2.0.50727.8015" test_ref="oval:org.mitre.oval:tst:138859"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment=".NET 3.5.1 and Win 7 / Server 2008 R2">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 3.5 SP1 is installed" definition_ref="oval:org.mitre.oval:def:12542"/>
          <criteria operator="OR" comment="gdr and ldr range">
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of System.Windows.Forms.dll is less than 2.0.50727.8653" test_ref="oval:org.mitre.oval:tst:138136"/>
              <criterion comment="Check if the version of System.Windows.Forms.dll is greater than or equal to 2.0.50727.8600" test_ref="oval:org.mitre.oval:tst:138704"/>
            </criteria>
            <criterion comment="Check if the version of System.Windows.Forms.dll is less than 2.0.50727.5491" test_ref="oval:org.mitre.oval:tst:137946"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment=".NET 4.0">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6749"/>
          <criteria operator="OR" comment="gdr and ldr range">
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of system.windows.forms.dll is less than 4.0.30319.2057" test_ref="oval:org.mitre.oval:tst:138799"/>
              <criterion comment="Check if version of System.Windows.Forms.dll is greater than or equal to 4.0.30319.2000" test_ref="oval:org.mitre.oval:tst:80817"/>
            </criteria>
            <criterion comment="Check if the version of system.windows.forms.dll is less than 4.0.30319.1032" test_ref="oval:org.mitre.oval:tst:138641"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment=".NET 4.5/4.5.1 and Win Vista / Win 7 / server 2008 / Server 2008 R2">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Either .Net 4.5 / 4.5.1 / 4.5.2 and version">
            <extend_definition comment="Microsoft .NET Framework 4.5 is installed" definition_ref="oval:org.mitre.oval:def:15925"/>
            <extend_definition comment="Microsoft .NET Framework 4.5.1 is installed" definition_ref="oval:org.mitre.oval:def:22275"/>
            <extend_definition comment="Microsoft .NET Framework 4.5.2 is installed" definition_ref="oval:org.mitre.oval:def:26546"/>
          </criteria>
          <criteria operator="OR" comment="Either file version">
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of system.windows.forms.dll is less than 4.0.30319.36287" test_ref="oval:org.mitre.oval:tst:138838"/>
              <criterion comment="Check if the version of system.windows.forms.dll is greater than or equal to 4.0.30319.36000" test_ref="oval:org.mitre.oval:tst:137962"/>
            </criteria>
            <criterion comment="Check if the version of system.windows.forms.dll is less than 4.0.30319.34251" test_ref="oval:org.mitre.oval:tst:138683"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment=".NET and Win 8 /Server 2012">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Either .Net 4.5 / 4.5.1 / 4.5.2 and version">
            <extend_definition comment="Microsoft .NET Framework 4.5 is installed" definition_ref="oval:org.mitre.oval:def:15925"/>
            <extend_definition comment="Microsoft .NET Framework 4.5.1 is installed" definition_ref="oval:org.mitre.oval:def:22275"/>
            <extend_definition comment="Microsoft .NET Framework 4.5.2 is installed" definition_ref="oval:org.mitre.oval:def:26546"/>
          </criteria>
          <criteria operator="OR" comment="Either file version">
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of system.windows.forms.dll is less than 4.0.30319.36286" test_ref="oval:org.mitre.oval:tst:138687"/>
              <criterion comment="Check if the version of system.windows.forms.dll is greater than or equal to 4.0.30319.36000" test_ref="oval:org.mitre.oval:tst:137962"/>
            </criteria>
            <criterion comment="Check if the version of system.windows.forms.dll is less than 4.0.30319.34250" test_ref="oval:org.mitre.oval:tst:138511"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment=".NET 4.5.1 / 4.5.2 and  Win 8.1 / Server 2012 R2">
          <criteria operator="OR" comment="Either .Net 4.5.1 / 4.5.2 version">
            <extend_definition comment="Microsoft .NET Framework 4.5.1 is installed" definition_ref="oval:org.mitre.oval:def:22275"/>
            <extend_definition comment="Microsoft .NET Framework 4.5.2 is installed" definition_ref="oval:org.mitre.oval:def:26546"/>
          </criteria>
          <criteria operator="OR" comment="Either OS">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criteria operator="OR" comment="Either file version">
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of system.windows.forms.dll is less than 4.0.30319.36286" test_ref="oval:org.mitre.oval:tst:138687"/>
              <criterion comment="Check if the version of system.windows.forms.dll is greater than or equal to 4.0.30319.36000" test_ref="oval:org.mitre.oval:tst:137962"/>
            </criteria>
            <criterion comment="Check if the version of system.windows.forms.dll is less than 4.0.30319.34250" test_ref="oval:org.mitre.oval:tst:138511"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28948" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-1755 (MS15-056)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-1755" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1755" source="CVE"/>
        <description>Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-1731, CVE-2015-1736, and CVE-2015-1737.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-16T04:41:39">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-06-18T10:14:28.677-04:00">DRAFT</status_change>
            <status_change date="2015-07-06T04:00:34.461-04:00">INTERIM</status_change>
            <status_change date="2015-07-27T04:00:45.797-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17377" test_ref="oval:org.mitre.oval:tst:139004"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21489" test_ref="oval:org.mitre.oval:tst:138844"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17842" test_ref="oval:org.mitre.oval:tst:138937"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28938" version="3" class="vulnerability">
      <metadata>
        <title>VBScript Memory corruption vulnerability - CVE-2015-2372 (MS15-065 and MS15-066)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft VBScript 5.6</product>
          <product>Microsoft VBScript 5.7</product>
          <product>Microsoft VBScript 5.8</product>
        </affected>
        <reference ref_id="CVE-2015-2372" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2372" source="CVE"/>
        <description>vbscript.dll in Microsoft VBScript 5.6 through 5.8, as used with Internet Explorer 6 through 11 and other products, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "VBScript Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-07-22T13:00:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-07-23T11:16:31.155-04:00">DRAFT</status_change>
            <status_change date="2015-08-10T04:00:40.445-04:00">INTERIM</status_change>
            <status_change date="2015-08-31T04:00:10.717-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="VBScript 5.6 and 2K3 vulnerable version">
          <criterion comment="vbscript.dll 5.6 or later is installed" test_ref="oval:org.mitre.oval:tst:100534"/>
          <criteria operator="OR" comment=" 2K3 + vulnerable file version">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of VBScript.dll is less than 5.6.0.8856" test_ref="oval:org.mitre.oval:tst:141230"/>
          <criterion comment="Internet Explorer 6 (any patch level) is installed" test_ref="oval:org.mitre.oval:tst:2333"/>
        </criteria>
        <criteria operator="AND" comment="VBScript 5.7 and 2K3/Vista/2k8 vulnerable version">
          <criterion comment="Vbscript.dll 5.7 or later is installed" test_ref="oval:org.mitre.oval:tst:11558"/>
          <criteria operator="OR" comment="2K3/Vista/2k8 vulnerable version">
            <criteria operator="AND" comment="2k3 and vulnerable file version">
              <criteria operator="OR" comment="2K3">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of VBScript.dll is less than 5.7.6002.23712" test_ref="oval:org.mitre.oval:tst:140314"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista / 2K8">
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of VBScript.dll is less than 5.7.6002.19405" test_ref="oval:org.mitre.oval:tst:141294"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of VBScript.dll is less than 5.7.6002.23712" test_ref="oval:org.mitre.oval:tst:140314"/>
                  <criterion comment="Check if the version of vbscript.dll is greater than or equal to 5.7.6002.23000" test_ref="oval:org.mitre.oval:tst:100298"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
          <criterion comment="Internet Explorer 7 is installed" test_ref="oval:org.mitre.oval:tst:178"/>
        </criteria>
        <criteria operator="AND" comment="Vbscript.dll 5.8 and vul version">
          <criterion comment="Vbscript.dll 5.8 or later is installed" test_ref="oval:org.mitre.oval:tst:11329"/>
          <criteria operator="OR" comment="2k8/Win7/2k8 R2/Win 8/Win 8.1/Win 2k12/Win 2k12 R2 vulnerable version">
            <criteria operator="AND" comment="VBScript 5.8 and 2K3/Vista/2k8/Win7/2k8 R2 + IE 8 vulnerable version">
              <criteria operator="OR" comment="2K3/Vista/2K8/Win7/R2 + VBScript 5.8 + vulnerable version">
                <criteria operator="AND" comment="2k3 and vulnerable version">
                  <criteria operator="OR" comment="2K3">
                    <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                    <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                  </criteria>
                  <criterion comment="Check if the version of vbscript.dll is less than 5.8.6001.23707" test_ref="oval:org.mitre.oval:tst:140824"/>
                </criteria>
                <criteria operator="AND" comment="Vista / 2K8 and vulnerable file version">
                  <criteria operator="OR" comment="Vista / 2K8">
                    <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                    <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                    <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                    <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                  </criteria>
                  <criteria operator="OR" comment="Check for vulnerable version">
                    <criterion comment="Check if the version of vbscript.dll is less than 5.8.6001.19652" test_ref="oval:org.mitre.oval:tst:141188"/>
                    <criteria operator="AND" comment="Check for LDR">
                      <criterion comment="Check if the version of vbscript.dll is less than 5.8.6001.23707" test_ref="oval:org.mitre.oval:tst:140824"/>
                      <criterion comment="Check if the version of Vbcript.dll is greater than or equal to 5.8.6001.23000" test_ref="oval:org.mitre.oval:tst:99962"/>
                    </criteria>
                  </criteria>
                </criteria>
                <criteria operator="AND" comment="Win7/R2 + vulnerable file version">
                  <criteria operator="OR" comment="Win7/R2">
                    <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                    <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                    <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                    <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
                  </criteria>
                  <criteria operator="OR" comment="vulnerable file version">
                    <criterion comment="Check if the version of vbscript.dll is less than 5.8.7601.18896" test_ref="oval:org.mitre.oval:tst:141265"/>
                    <criteria operator="AND" comment="Check for LDR">
                      <criterion comment="Check if the version of vbscript.dll is less than 5.8.7601.23099" test_ref="oval:org.mitre.oval:tst:140984"/>
                      <criterion comment="Check if the version of vbscript.dll is greater than or equal to 5.8.7601.23000" test_ref="oval:org.mitre.oval:tst:138193"/>
                    </criteria>
                  </criteria>
                </criteria>
              </criteria>
              <criterion comment="Internet Explorer 8 is installed" test_ref="oval:org.mitre.oval:tst:9082"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8/Win7/R2 and IE 9 + vulnerable file version">
              <criteria operator="OR" comment="Vista / 2K8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of vbscript.dll is less than 5.8.7601.17174" test_ref="oval:org.mitre.oval:tst:140884"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Vbscript.dll version is greater than or equal 5.8.7601.20000" test_ref="oval:org.mitre.oval:tst:41925"/>
                  <criterion comment="Check if the version of vbscript.dll is less than 5.8.7601.20785" test_ref="oval:org.mitre.oval:tst:141278"/>
                </criteria>
              </criteria>
              <criterion comment="Internet Explorer 9 is installed" test_ref="oval:org.mitre.oval:tst:42359"/>
            </criteria>
            <criteria operator="AND" comment="Win7/R2/Win8/2k12 and IE 10 + vulnerable file version">
              <criterion comment="Check if Microsoft Internet Explorer 10 is installed" test_ref="oval:org.mitre.oval:tst:80429"/>
              <criteria operator="OR" comment="Win7/R2/Win8/2k12 + VBScript 5.8 + vulnerable version">
                <criteria operator="AND" comment="Win7/R2 and IE 10 + vulnerable file version">
                  <criteria operator="OR" comment="Win7/R2">
                    <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                    <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                    <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                    <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
                    <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
                    <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
                  </criteria>
                  <criteria operator="OR" comment="Check for vulnerable version">
                    <criterion comment="Check if the version of vbscript.dll is less than 5.8.9200.17410" test_ref="oval:org.mitre.oval:tst:140995"/>
                    <criteria operator="AND" comment="Check for LDR">
                      <criterion comment="Check if the version of vbscript.dll is greater than or equal to 5.8.9200.21000" test_ref="oval:org.mitre.oval:tst:135738"/>
                      <criterion comment="Check if the version of vbscript.dll is less than 5.8.9200.21521" test_ref="oval:org.mitre.oval:tst:141291"/>
                    </criteria>
                  </criteria>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win7/2k8 R2/Win8.1/2k12 R2 and IE 11 + vulnerable file version">
              <criteria operator="OR" comment="Win7/2k8 R2/Win8.1/2k12 R2 and vulnerable file version">
                <criteria operator="AND" comment="Win7 x86 and vulnerable version">
                  <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                  <criterion comment="Check if the version of vbscript.dll is less than 5.8.9600.17909" test_ref="oval:org.mitre.oval:tst:141182"/>
                </criteria>
                <criteria operator="AND" comment="Win7 x64 / Server 2008 R2 and vulnerable version">
                  <criteria operator="OR" comment="Win 7 / R2">
                    <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                    <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                  </criteria>
                  <criterion comment="Check if the version of vbscript.dll is less than 5.8.9600.17910" test_ref="oval:org.mitre.oval:tst:141085"/>
                </criteria>
                <criteria operator="AND" comment="Win 8.1  / Server 2012 R2 and vulnerable version">
                  <criteria operator="OR" comment="Win 7 / R2">
                    <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                    <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                    <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
                  </criteria>
                  <criterion comment="Check if the version of vbscript.dll is less than 5.8.9600.17905" test_ref="oval:org.mitre.oval:tst:140873"/>
                </criteria>
              </criteria>
              <criterion comment="Check if Microsoft Internet Explorer 11 is installed" test_ref="oval:org.mitre.oval:tst:87142"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28936" version="3" class="vulnerability">
      <metadata>
        <title>Windows Journal remote code execution vulnerability - CVE-2015-1699 (MS15-045)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-1699" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1699"/>
        <description>Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allow remote attackers to execute arbitrary code via a crafted Journal file, aka "Windows Journal Remote Code Execution Vulnerability," a different vulnerability than CVE-2015-1675, CVE-2015-1695, CVE-2015-1696, CVE-2015-1697, and CVE-2015-1698.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-05-20T18:56:32">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-05-28T14:32:49.383-04:00">DRAFT</status_change>
            <status_change date="2015-06-15T04:00:30.836-04:00">INTERIM</status_change>
            <status_change date="2015-07-06T04:00:34.221-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vista / 2k8 + vulnerable file version">
          <criteria operator="OR" comment="Vista / 2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Journal.dll is less than 6.0.6002.23664" test_ref="oval:org.mitre.oval:tst:138166"/>
              <criterion comment="Check if the version of Journal.dll is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:138660"/>
            </criteria>
            <criterion comment="Check if the version of Journal.dll is less than 6.0.6002.19356" test_ref="oval:org.mitre.oval:tst:138728"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / R2 + vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Journal.dll is less than 6.1.7601.23020" test_ref="oval:org.mitre.oval:tst:138830"/>
              <criterion comment="Check if the version of Journal.dll is greater than or equal to 6.1.7601.23000" test_ref="oval:org.mitre.oval:tst:138508"/>
            </criteria>
            <criterion comment="Check if the version of Journal.dll is less than 6.1.7601.18815" test_ref="oval:org.mitre.oval:tst:138819"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8/2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Journal.dll is less than 6.2.9200.21444" test_ref="oval:org.mitre.oval:tst:138174"/>
              <criterion comment="Check if the version of Journal.dll is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:138277"/>
            </criteria>
            <criterion comment="Check if the version of Journal.dll is less than 6.2.9200.17330" test_ref="oval:org.mitre.oval:tst:138698"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1 / 2K12 R2and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of Journal.dll is less than 6.3.9600.17793" test_ref="oval:org.mitre.oval:tst:138477"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28932" version="3" class="vulnerability">
      <metadata>
        <title>Service control manager elevation of privilege vulnerability - CVE-2015-1702 (MS15-050)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-1702" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1702"/>
        <description>The Service Control Manager (SCM) in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 does not properly constrain impersonation levels, which allows local users to gain privileges via a crafted application, aka "Service Control Manager Elevation of Privilege Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-05-20T18:39:47">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-05-28T14:37:09.571-04:00">DRAFT</status_change>
            <status_change date="2015-06-15T04:00:30.416-04:00">INTERIM</status_change>
            <status_change date="2015-07-06T04:00:33.568-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
          <criteria operator="OR" comment="Vista / 2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of services.exe is less than 6.0.6002.19369" test_ref="oval:org.mitre.oval:tst:138682"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of services.exe is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:138469"/>
              <criterion comment="Check if the version of services.exe is less than 6.0.6002.23677" test_ref="oval:org.mitre.oval:tst:138468"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / R2 and vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of services.exe is less than 6.1.7601.18829" test_ref="oval:org.mitre.oval:tst:138200"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of services.exe is greater than or equal to 6.1.7601.23000" test_ref="oval:org.mitre.oval:tst:138798"/>
              <criterion comment="Check if the version of services.exe is less than 6.1.7601.23033" test_ref="oval:org.mitre.oval:tst:138581"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Windows 8 / 2k12 and vulnerable file version">
          <criteria operator="OR" comment="Windows 8/2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of services.exe is less than 6.2.9200.17343" test_ref="oval:org.mitre.oval:tst:138750"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of services.exe is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:138360"/>
              <criterion comment="Check if the version of services.exe is less than 6.2.9200.21456" test_ref="oval:org.mitre.oval:tst:138573"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Windows 8.1/2k12 R2 and vulnerable file version">
          <criteria operator="OR" comment="Windows 8.1 / 2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of services.exe is less than 6.3.9600.17793" test_ref="oval:org.mitre.oval:tst:137869"/>
        </criteria>
        <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
        <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
        <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28924" version="4" class="vulnerability">
      <metadata>
        <title>Microsoft SharePoint page content vulnerabilities – CVE-2015-1700 (MS15-047)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <product>Microsoft SharePoint Server 2007</product>
          <product>Microsoft SharePoint Server 2010</product>
          <product>Microsoft SharePoint Foundation 2010</product>
          <product>Microsoft SharePoint Foundation 2013</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-1700" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1700"/>
        <description>Microsoft SharePoint Server 2007 SP3, SharePoint Foundation 2010 SP2, SharePoint Server 2010 SP2, and SharePoint Foundation 2013 SP1 allow remote authenticated users to execute arbitrary code via crafted page content, aka "Microsoft SharePoint Page Content Vulnerabilities."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-05-20T20:21:11">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-05-28T14:09:54.328-04:00">DRAFT</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:1569 - MS Bulletins - May 2015" date="2015-05-28T14:06:00.511-04:00">
              <contributor organization="SecPod Technologies">Kumarswamy S</contributor>
            </modified>
            <status_change date="2015-06-15T04:00:30.063-04:00">INTERIM</status_change>
            <status_change date="2015-07-06T04:00:33.059-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Sharepoint 2007 and vulnerable file versions">
          <extend_definition comment="Microsoft Office SharePoint Server 2007 is installed." definition_ref="oval:org.mitre.oval:def:2313"/>
          <criterion comment="Check if the version of Microsoft.SharePoint.Portal.dll is less than 12.0.6721.5000" test_ref="oval:org.mitre.oval:tst:137831"/>
        </criteria>
        <criteria operator="AND" comment="Sharepoint 2010 and vulnerable file version">
          <extend_definition comment="Microsoft Office SharePoint Server 2010 is installed." definition_ref="oval:org.mitre.oval:def:12880"/>
          <criterion comment="Check if the version of Microsoft.office.policy.dll is less than 14.0.7149.5000" test_ref="oval:org.mitre.oval:tst:138630"/>
        </criteria>
        <criteria operator="AND" comment="Sharepoint Foundation 2010 / 2010 SP1">
          <extend_definition comment="Microsoft SharePoint Foundation 2010 is installed" definition_ref="oval:org.mitre.oval:def:12224"/>
          <criterion comment="Check if the version of onetutil.dll is less than 14.0.7149.5000" test_ref="oval:org.mitre.oval:tst:138555"/>
        </criteria>
        <criteria operator="AND" comment="Sharepoint Foundation 2013 and vulnerable file version">
          <extend_definition comment="Microsoft SharePoint Foundation 2013 is installed" definition_ref="oval:org.mitre.oval:def:19090"/>
          <criterion comment="Check if the version of stswel.dll is less than 15.0.4719.1002" test_ref="oval:org.mitre.oval:tst:138608"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2313" version="12" class="inventory">
      <metadata>
        <title>Microsoft Office SharePoint Server 2007 is installed.</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <product>Microsoft Office SharePoint Server 2007</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:sharepoint_server:2007"/>
        <description>Microsoft Office SharePoint Server 2007 is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-10-10T04:39:42">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2007-10-11T10:02:51.975-04:00">DRAFT</status_change>
            <status_change date="2007-10-26T10:00:30.934-04:00">INTERIM</status_change>
            <status_change date="2007-11-13T12:01:08.127-05:00">ACCEPTED</status_change>
            <modified comment="Changed datatype from version to string." date="2008-08-28T13:32:00.278-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2008-08-28T13:44:16.491-04:00">INTERIM</status_change>
            <status_change date="2008-09-15T04:00:21.134-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:2313 - Modifications vary from minor OVAL title/description changes to suggesting an alternative CPE name to use." date="2011-09-28T11:29:00.976-04:00">
              <contributor organization="The MITRE Corporation">David Rothenberg</contributor>
            </modified>
            <status_change date="2011-09-28T11:33:38.747-04:00">INTERIM</status_change>
            <status_change date="2011-10-17T04:00:18.536-04:00">ACCEPTED</status_change>
            <status_change date="2012-03-05T14:24:07.072-05:00">INTERIM</status_change>
            <modified comment="Added Windows Server 2008 R2 platform" date="2012-03-05T14:24:07.072-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-03-26T04:03:00.785-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:2686 - MS13-084, 085 and 067 bulletins" date="2013-10-23T11:46:00.610-04:00">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </modified>
            <status_change date="2013-10-23T11:49:25.573-04:00">INTERIM</status_change>
            <status_change date="2013-11-11T04:02:03.519-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:2686 - In some &quot;pattern match&quot; strings added &quot;\&quot; before &quot;.&quot; to clarify if &quot;point&quot; or &quot;any symbol&quot; needed." date="2014-07-28T18:11:00.493-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-07-28T18:12:36.194-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:02:26.510-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:2313 - removed Microsoft Exchange Server 2003 from inventory" date="2015-06-05T09:04:00.152-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-06-05T09:06:27.662-04:00">INTERIM</status_change>
            <status_change date="2015-06-22T04:00:42.619-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="SharePoint Server 2007 is installed." test_ref="oval:org.mitre.oval:tst:4279"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28917" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-1718 (MS15-043)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-1718" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1718" source="CVE"/>
        <description>Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-1658, CVE-2015-1706, CVE-2015-1711, and CVE-2015-1717.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-05-20T08:43:05">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-05-28T14:15:59.485-04:00">DRAFT</status_change>
            <status_change date="2015-06-15T04:00:29.917-04:00">INTERIM</status_change>
            <status_change date="2015-07-06T04:00:32.866-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
        <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
          <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
          <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
          <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
          <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
          <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
        </criteria>
        <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17801" test_ref="oval:org.mitre.oval:tst:138184"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28895" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-1668 (MS15-032)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-1668" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1668" source="CVE"/>
        <description>Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-04-21T10:59:59">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-04-24T09:24:04.735-04:00">DRAFT</status_change>
            <status_change date="2015-05-11T04:00:24.960-04:00">INTERIM</status_change>
            <status_change date="2015-06-01T04:00:22.760-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17296" test_ref="oval:org.mitre.oval:tst:138031"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21413" test_ref="oval:org.mitre.oval:tst:138588"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17728" test_ref="oval:org.mitre.oval:tst:138275"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28889" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-1736 (MS15-056)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-1736" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1736" source="CVE"/>
        <description>Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-1731, CVE-2015-1737, and CVE-2015-1755.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-16T04:41:39">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-06-18T10:14:29.962-04:00">DRAFT</status_change>
            <status_change date="2015-07-06T04:00:32.196-04:00">INTERIM</status_change>
            <status_change date="2015-07-27T04:00:39.995-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17377" test_ref="oval:org.mitre.oval:tst:139004"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21489" test_ref="oval:org.mitre.oval:tst:138844"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17842" test_ref="oval:org.mitre.oval:tst:138937"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28876" version="3" class="vulnerability">
      <metadata>
        <title>Microsoft windows kernel memory disclosure vulnerability - CVE-2015-1677 (MS15-051)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-1677" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1677"/>
        <description>The kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allow local users to bypass the ASLR protection mechanism via a crafted function call, aka "Microsoft Windows Kernel Memory Disclosure Vulnerability," a different vulnerability than CVE-2015-1676, CVE-2015-1678, CVE-2015-1679, and CVE-2015-1680.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-05-20T18:56:32">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-05-28T14:30:20.752-04:00">DRAFT</status_change>
            <status_change date="2015-06-15T04:00:29.368-04:00">INTERIM</status_change>
            <status_change date="2015-07-06T04:00:31.700-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Windows Server 2k3 and vulnerable file version">
          <criteria operator="OR" comment="Either OS">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of win32k.sys is less than 5.2.3790.5615" test_ref="oval:org.mitre.oval:tst:138664"/>
        </criteria>
        <criteria operator="AND" comment="Vista / 2k8 + vulnerable file version">
          <criteria operator="OR" comment="Vista / 2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:81723"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.0.6002.23680" test_ref="oval:org.mitre.oval:tst:138658"/>
            </criteria>
            <criterion comment="Check if the version of win32k.sys is less than 6.0.6002.19372" test_ref="oval:org.mitre.oval:tst:138686"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / R2 + vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.1.7601.23000" test_ref="oval:org.mitre.oval:tst:138862"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.23038" test_ref="oval:org.mitre.oval:tst:138649"/>
            </criteria>
            <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.18834" test_ref="oval:org.mitre.oval:tst:138724"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8/2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:115678"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.21457" test_ref="oval:org.mitre.oval:tst:138582"/>
            </criteria>
            <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.17343" test_ref="oval:org.mitre.oval:tst:138343"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1 / 2K12 R2and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of win32k.sys is less than 6.3.9600.17796" test_ref="oval:org.mitre.oval:tst:138198"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28861" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-1666 (MS15-032)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-1666" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1666" source="CVE"/>
        <description>Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-1652.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-04-21T10:59:59">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-04-24T09:24:18.735-04:00">DRAFT</status_change>
            <status_change date="2015-05-11T04:00:23.867-04:00">INTERIM</status_change>
            <status_change date="2015-06-01T04:00:22.054-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5569" test_ref="oval:org.mitre.oval:tst:138423"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21448" test_ref="oval:org.mitre.oval:tst:138618"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista / 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19334" test_ref="oval:org.mitre.oval:tst:138373"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23642" test_ref="oval:org.mitre.oval:tst:138546"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23671" test_ref="oval:org.mitre.oval:tst:138606"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19612" test_ref="oval:org.mitre.oval:tst:138331"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23671" test_ref="oval:org.mitre.oval:tst:138606"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18806" test_ref="oval:org.mitre.oval:tst:138424"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.23010" test_ref="oval:org.mitre.oval:tst:137911"/>
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.23000" test_ref="oval:org.mitre.oval:tst:138202"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16636" test_ref="oval:org.mitre.oval:tst:138537"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20750" test_ref="oval:org.mitre.oval:tst:137976"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17296" test_ref="oval:org.mitre.oval:tst:138031"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21413" test_ref="oval:org.mitre.oval:tst:138588"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17728" test_ref="oval:org.mitre.oval:tst:138275"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28848" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-1744 (MS15-056)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-1744" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1744" source="CVE"/>
        <description>Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-1735, CVE-2015-1740, CVE-2015-1745, and CVE-2015-1766.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-16T04:41:39">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-06-18T10:14:25.941-04:00">DRAFT</status_change>
            <status_change date="2015-07-06T04:00:30.250-04:00">INTERIM</status_change>
            <status_change date="2015-07-27T04:00:37.509-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5624" test_ref="oval:org.mitre.oval:tst:138803"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21466" test_ref="oval:org.mitre.oval:tst:138892"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista / 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19383" test_ref="oval:org.mitre.oval:tst:138665"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23690" test_ref="oval:org.mitre.oval:tst:139050"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23687" test_ref="oval:org.mitre.oval:tst:138276"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19632" test_ref="oval:org.mitre.oval:tst:138942"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23687" test_ref="oval:org.mitre.oval:tst:138276"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18870" test_ref="oval:org.mitre.oval:tst:138751"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.23073" test_ref="oval:org.mitre.oval:tst:138584"/>
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.23000" test_ref="oval:org.mitre.oval:tst:138202"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16659" test_ref="oval:org.mitre.oval:tst:138475"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20774" test_ref="oval:org.mitre.oval:tst:138843"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17377" test_ref="oval:org.mitre.oval:tst:139004"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21489" test_ref="oval:org.mitre.oval:tst:138844"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17842" test_ref="oval:org.mitre.oval:tst:138937"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28847" version="3" class="vulnerability">
      <metadata>
        <title>Remote desktop protocol (RDP) denial of service vulnerability - CVE-2015-0079 (MS15-030)</title>
        <affected family="windows">
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-0079" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0079"/>
        <description>The Remote Desktop Protocol (RDP) implementation in Microsoft Windows 7 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 allows remote attackers to cause a denial of service (memory consumption and RDP outage) by establishing many RDP sessions that do not properly free allocated memory, aka "Remote Desktop Protocol (RDP) Denial of Service Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-03-16T09:23:57">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-03-17T11:35:32.118-04:00">DRAFT</status_change>
            <status_change date="2015-04-06T04:00:16.961-04:00">INTERIM</status_change>
            <status_change date="2015-04-27T04:00:27.037-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Win 7 / R2 + vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of rdpcorets.dll is less than 6.1.7601.18740" test_ref="oval:org.mitre.oval:tst:138435"/>
            <criteria operator="AND" comment="LDR range">
              <criterion comment="Check if the version of rdpcorets.dll is less than 6.1.7601.22947" test_ref="oval:org.mitre.oval:tst:138342"/>
              <criterion comment="Check if the version of rdpcorets.dll is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:114959"/>
            </criteria>
            <criteria operator="AND" comment="rdpcorets.dll with version range 6.2.9200.xxxx">
              <criteria operator="OR" comment="gdr/ldr">
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of rdpcorets.dll is less than 6.2.9200.21172" test_ref="oval:org.mitre.oval:tst:138455"/>
                  <criterion comment="Check if the version of rdpcorets.dll is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:114938"/>
                </criteria>
                <criterion comment="Check if the version of rdpcorets.dll is less than 6.2.9200.17053" test_ref="oval:org.mitre.oval:tst:138420"/>
              </criteria>
              <criterion comment="Check if the version of rdpcorets.dll is greater than or equal to 6.2.9200.00000" test_ref="oval:org.mitre.oval:tst:137511"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8/2k12 and vulnerable file version">
          <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of rdpcorets.dll is less than 6.2.9200.17247" test_ref="oval:org.mitre.oval:tst:138347"/>
            <criteria operator="AND" comment="Check for LDR range">
              <criterion comment="Check if the version of rdpcorets.dll is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:114938"/>
              <criterion comment="Check if the version of rdpcorets.dll is less than 6.2.9200.21364" test_ref="oval:org.mitre.oval:tst:138201"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8/2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criteria operator="AND" comment="Check for LDR range">
              <criterion comment="Check if the version of Rdpudd.dll is less than 6.2.9200.21364" test_ref="oval:org.mitre.oval:tst:138456"/>
              <criterion comment="Check if the version of Rdpudd.dll is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:138064"/>
            </criteria>
            <criterion comment="Check if the version of Rdpudd.dll is less than 6.2.9200.17247" test_ref="oval:org.mitre.oval:tst:137632"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1 / 2K12 R2and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of rdpcorets.dll is less than 6.3.9600.17667" test_ref="oval:org.mitre.oval:tst:138398"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28843" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-1624 (MS15-018)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-1624" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1624" source="CVE"/>
        <description>Microsoft Internet Explorer 8 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-03-16T09:23:57">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-03-17T10:36:27.309-04:00">DRAFT</status_change>
            <status_change date="2015-04-06T04:00:16.411-04:00">INTERIM</status_change>
            <status_change date="2015-04-27T04:00:26.284-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23661" test_ref="oval:org.mitre.oval:tst:138196"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19607" test_ref="oval:org.mitre.oval:tst:138058"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23661" test_ref="oval:org.mitre.oval:tst:138196"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18751" test_ref="oval:org.mitre.oval:tst:137478"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22958" test_ref="oval:org.mitre.oval:tst:138221"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16633" test_ref="oval:org.mitre.oval:tst:137971"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20747" test_ref="oval:org.mitre.oval:tst:137783"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17267" test_ref="oval:org.mitre.oval:tst:138160"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21384" test_ref="oval:org.mitre.oval:tst:138199"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17690" test_ref="oval:org.mitre.oval:tst:138148"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28834" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-2406 (MS15-065)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-2406" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2406" source="CVE"/>
        <description>Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-2385, CVE-2015-2390, CVE-2015-2397, CVE-2015-2404, and CVE-2015-2422.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-07-22T13:00:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-07-23T11:16:27.990-04:00">DRAFT</status_change>
            <status_change date="2015-08-10T04:00:39.346-04:00">INTERIM</status_change>
            <status_change date="2015-08-31T04:00:10.001-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5662" test_ref="oval:org.mitre.oval:tst:140298"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21481" test_ref="oval:org.mitre.oval:tst:140959"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista / 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19421" test_ref="oval:org.mitre.oval:tst:140954"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23728" test_ref="oval:org.mitre.oval:tst:141086"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23707" test_ref="oval:org.mitre.oval:tst:141287"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19652" test_ref="oval:org.mitre.oval:tst:141242"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23707" test_ref="oval:org.mitre.oval:tst:141287"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18896" test_ref="oval:org.mitre.oval:tst:141220"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.23099" test_ref="oval:org.mitre.oval:tst:141285"/>
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.23000" test_ref="oval:org.mitre.oval:tst:138202"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16669" test_ref="oval:org.mitre.oval:tst:141203"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20784" test_ref="oval:org.mitre.oval:tst:141111"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17412" test_ref="oval:org.mitre.oval:tst:140758"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21523" test_ref="oval:org.mitre.oval:tst:141225"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17905" test_ref="oval:org.mitre.oval:tst:141110"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28831" version="3" class="vulnerability">
      <metadata>
        <title>NtCreateTransactionManager type confusion vulnerability - CVE-2015-1643 (MS15-038)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 8.1</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-1643" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1643"/>
        <description>Microsoft Windows Server 2003 R2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 do not properly constrain impersonation levels, which allows local users to gain privileges via a crafted application, aka "NtCreateTransactionManager Type Confusion Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-04-17T12:36:08">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-04-23T10:20:34.323-04:00">DRAFT</status_change>
            <status_change date="2015-05-11T04:00:22.974-04:00">INTERIM</status_change>
            <status_change date="2015-06-01T04:00:21.658-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vista/2k8 and vulnerable file version">
          <criteria operator="OR" comment="Vista/2k8(x86/x64/ia64)">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of Clfsw32.dll is less than 6.0.6002.19331" test_ref="oval:org.mitre.oval:tst:138203"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Clfsw32.dll is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:138245"/>
              <criterion comment="Check if the version of Clfsw32.dll is less than 6.0.6002.23639" test_ref="oval:org.mitre.oval:tst:138205"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / R2 and vulnerable file version">
          <criteria operator="OR" comment="Win 7/ R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of Clfsw32.dll is less than 6.1.7601.18777" test_ref="oval:org.mitre.oval:tst:137624"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Clfsw32.dll is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:138543"/>
              <criterion comment="Check if the version of Clfsw32.dll is less than 6.1.7601.22981" test_ref="oval:org.mitre.oval:tst:138480"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8 / 2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8/2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of Clfsw32.dll is less than 6.2.9200.17291" test_ref="oval:org.mitre.oval:tst:138549"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Clfsw32.dll is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:138180"/>
              <criterion comment="Check if the version of Clfsw32.dll is less than 6.2.9200.21408" test_ref="oval:org.mitre.oval:tst:138574"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1/Server 2012 R2 and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of Clfsw32.dll is less than 6.3.9600.17719" test_ref="oval:org.mitre.oval:tst:138112"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28829" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer elevation of privilege vulnerability - CVE-2015-1713 (MS15-043)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-1713" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1713" source="CVE"/>
        <description>Microsoft Internet Explorer 11 allows remote attackers to gain privileges via a crafted web site, aka "Internet Explorer Elevation of Privilege Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-05-20T08:43:05">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-05-28T14:16:28.086-04:00">DRAFT</status_change>
            <status_change date="2015-06-15T04:00:28.494-04:00">INTERIM</status_change>
            <status_change date="2015-07-06T04:00:29.728-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
        <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
          <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
          <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
          <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
          <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
          <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
        </criteria>
        <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17801" test_ref="oval:org.mitre.oval:tst:138184"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28822" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer clipboard information disclosure vulnerability - CVE-2015-1692 (MS15-043)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-1692" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1692" source="CVE"/>
        <description>Microsoft Internet Explorer 7 through 11 allows user-assisted remote attackers to read the clipboard contents via crafted web script, aka "Internet Explorer Clipboard Information Disclosure Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-05-20T08:43:05">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-05-28T14:16:10.583-04:00">DRAFT</status_change>
            <status_change date="2015-06-15T04:00:28.214-04:00">INTERIM</status_change>
            <status_change date="2015-07-06T04:00:29.293-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21455" test_ref="oval:org.mitre.oval:tst:138315"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista / 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19367" test_ref="oval:org.mitre.oval:tst:137942"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23675" test_ref="oval:org.mitre.oval:tst:138544"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23676" test_ref="oval:org.mitre.oval:tst:138485"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19621" test_ref="oval:org.mitre.oval:tst:138412"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23676" test_ref="oval:org.mitre.oval:tst:138485"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18835" test_ref="oval:org.mitre.oval:tst:138592"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.23038" test_ref="oval:org.mitre.oval:tst:137853"/>
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.23000" test_ref="oval:org.mitre.oval:tst:138202"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16644" test_ref="oval:org.mitre.oval:tst:138514"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20758" test_ref="oval:org.mitre.oval:tst:138561"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17357" test_ref="oval:org.mitre.oval:tst:138213"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21470" test_ref="oval:org.mitre.oval:tst:138585"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17801" test_ref="oval:org.mitre.oval:tst:138184"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28821" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer ASLR bypass vulnerability - CVE-2015-1661 (MS15-032)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-1661" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1661" source="CVE"/>
        <description>Microsoft Internet Explorer 6 through 11 allows remote attackers to bypass the ASLR protection mechanism via a crafted web site, aka "Internet Explorer ASLR Bypass Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-04-21T10:59:59">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-04-24T09:24:08.311-04:00">DRAFT</status_change>
            <status_change date="2015-05-11T04:00:22.648-04:00">INTERIM</status_change>
            <status_change date="2015-06-01T04:00:21.324-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5569" test_ref="oval:org.mitre.oval:tst:138423"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21448" test_ref="oval:org.mitre.oval:tst:138618"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista / 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19334" test_ref="oval:org.mitre.oval:tst:138373"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23642" test_ref="oval:org.mitre.oval:tst:138546"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23671" test_ref="oval:org.mitre.oval:tst:138606"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19612" test_ref="oval:org.mitre.oval:tst:138331"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23671" test_ref="oval:org.mitre.oval:tst:138606"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18806" test_ref="oval:org.mitre.oval:tst:138424"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.23010" test_ref="oval:org.mitre.oval:tst:137911"/>
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.23000" test_ref="oval:org.mitre.oval:tst:138202"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16636" test_ref="oval:org.mitre.oval:tst:138537"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20750" test_ref="oval:org.mitre.oval:tst:137976"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17296" test_ref="oval:org.mitre.oval:tst:138031"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21413" test_ref="oval:org.mitre.oval:tst:138588"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17728" test_ref="oval:org.mitre.oval:tst:138275"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28818" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-1733 (MS15-065)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-1733" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1733" source="CVE"/>
        <description>Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-2389 and CVE-2015-2411.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-07-22T13:00:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-07-23T11:16:16.364-04:00">DRAFT</status_change>
            <status_change date="2015-08-10T04:00:39.118-04:00">INTERIM</status_change>
            <status_change date="2015-08-31T04:00:09.617-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17412" test_ref="oval:org.mitre.oval:tst:140758"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21523" test_ref="oval:org.mitre.oval:tst:141225"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17905" test_ref="oval:org.mitre.oval:tst:141110"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28816" version="3" class="vulnerability">
      <metadata>
        <title>Registry virtualization elevation of privilege vulnerability - CVE-2015-0073 (MS15-025)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-0073" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0073"/>
        <description>The Windows Registry Virtualization feature in the kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 does not properly restrict changes to virtual stores, which allows local users to gain privileges via a crafted application, aka "Registry Virtualization Elevation of Privilege Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-03-16T09:23:57">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-03-17T11:19:02.985-04:00">DRAFT</status_change>
            <status_change date="2015-04-06T04:00:15.992-04:00">INTERIM</status_change>
            <status_change date="2015-04-27T04:00:25.548-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vista / 2k8 + vulnerable file version">
          <criteria operator="OR" comment="Vista / 2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="Check for LDR/GDR">
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Ntoskrnl.exe is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80719"/>
              <criterion comment="Check if the version of Ntoskrnl.exe is less than 6.0.6002.23636" test_ref="oval:org.mitre.oval:tst:138397"/>
            </criteria>
            <criterion comment="Check if the version of Ntoskrnl.exe is less than 6.0.6002.19327" test_ref="oval:org.mitre.oval:tst:137988"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / R2 + vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="Check for LDR/GDR">
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Ntoskrnl.exe is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:81000"/>
              <criterion comment="Check if the version of Ntoskrnl.exe is less than 6.1.7601.22943" test_ref="oval:org.mitre.oval:tst:138117"/>
            </criteria>
            <criterion comment="Check if the version of Ntoskrnl.exe is less than 6.1.7601.18738" test_ref="oval:org.mitre.oval:tst:138289"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8 (x86) and vulnerable file version">
          <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Ntoskrnl.exe is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:137068"/>
              <criterion comment="Check if the version of Ntoskrnl.exe is less than 6.2.9200.21368" test_ref="oval:org.mitre.oval:tst:138325"/>
            </criteria>
            <criterion comment="Check if the version of Ntoskrnl.exe is less than 6.2.9200.17251" test_ref="oval:org.mitre.oval:tst:138231"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8 (x64)/2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 (x64) / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Ntoskrnl.exe is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:137068"/>
              <criterion comment="Check if the version of Ntoskrnl.exe is less than 6.2.9200.21369" test_ref="oval:org.mitre.oval:tst:138237"/>
            </criteria>
            <criterion comment="Check if the version of Ntoskrnl.exe is less than 6.2.9200.17251" test_ref="oval:org.mitre.oval:tst:138231"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1 / 2K12 R2and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of Ntoskrnl.exe is less than 6.3.9600.17668" test_ref="oval:org.mitre.oval:tst:138192"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28815" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer elevation of privilege vulnerability - CVE-2015-1704 (MS15-043)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-1704" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1704" source="CVE"/>
        <description>Microsoft Internet Explorer 6 through 11 allows remote attackers to gain privileges via a crafted web site, aka "Internet Explorer Elevation of Privilege Vulnerability," a different vulnerability than CVE-2015-1703.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-05-20T08:43:05">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-05-28T14:16:02.152-04:00">DRAFT</status_change>
            <status_change date="2015-06-15T04:00:27.706-04:00">INTERIM</status_change>
            <status_change date="2015-07-06T04:00:28.719-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5602" test_ref="oval:org.mitre.oval:tst:138124"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21455" test_ref="oval:org.mitre.oval:tst:138315"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista / 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19367" test_ref="oval:org.mitre.oval:tst:137942"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23675" test_ref="oval:org.mitre.oval:tst:138544"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23676" test_ref="oval:org.mitre.oval:tst:138485"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19621" test_ref="oval:org.mitre.oval:tst:138412"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23676" test_ref="oval:org.mitre.oval:tst:138485"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18835" test_ref="oval:org.mitre.oval:tst:138592"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.23038" test_ref="oval:org.mitre.oval:tst:137853"/>
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.23000" test_ref="oval:org.mitre.oval:tst:138202"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16644" test_ref="oval:org.mitre.oval:tst:138514"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20758" test_ref="oval:org.mitre.oval:tst:138561"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17357" test_ref="oval:org.mitre.oval:tst:138213"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21470" test_ref="oval:org.mitre.oval:tst:138585"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17801" test_ref="oval:org.mitre.oval:tst:138184"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28813" version="3" class="vulnerability">
      <metadata>
        <title>Win32k elevation of privilege vulnerability - CVE-2015-0078 (MS15-023)</title>
        <affected family="windows">
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-0078" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0078"/>
        <description>win32k.sys in the kernel-mode drivers in Microsoft Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 does not properly validate the token of a calling thread, which allows local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-03-16T09:23:57">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-03-17T10:55:32.567-04:00">DRAFT</status_change>
            <status_change date="2015-04-06T04:00:15.885-04:00">INTERIM</status_change>
            <status_change date="2015-04-27T04:00:25.357-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Win 8/2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.17287" test_ref="oval:org.mitre.oval:tst:138063"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:115678"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.21403" test_ref="oval:org.mitre.oval:tst:138335"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1 / 2K12 R2and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of win32k.sys is less than 6.3.9600.17694" test_ref="oval:org.mitre.oval:tst:138216"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28808" version="3" class="vulnerability">
      <metadata>
        <title>Microsoft windows kernel memory disclosure vulnerability - CVE-2015-1680 (MS15-051)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-1680" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1680"/>
        <description>The kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allow local users to bypass the ASLR protection mechanism via a crafted function call, aka "Microsoft Windows Kernel Memory Disclosure Vulnerability," a different vulnerability than CVE-2015-1676, CVE-2015-1677, CVE-2015-1678, and CVE-2015-1679.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-05-20T18:56:32">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-05-28T14:30:25.622-04:00">DRAFT</status_change>
            <status_change date="2015-06-15T04:00:27.428-04:00">INTERIM</status_change>
            <status_change date="2015-07-06T04:00:28.314-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Windows Server 2k3 and vulnerable file version">
          <criteria operator="OR" comment="Either OS">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of win32k.sys is less than 5.2.3790.5615" test_ref="oval:org.mitre.oval:tst:138664"/>
        </criteria>
        <criteria operator="AND" comment="Vista / 2k8 + vulnerable file version">
          <criteria operator="OR" comment="Vista / 2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:81723"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.0.6002.23680" test_ref="oval:org.mitre.oval:tst:138658"/>
            </criteria>
            <criterion comment="Check if the version of win32k.sys is less than 6.0.6002.19372" test_ref="oval:org.mitre.oval:tst:138686"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / R2 + vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.1.7601.23000" test_ref="oval:org.mitre.oval:tst:138862"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.23038" test_ref="oval:org.mitre.oval:tst:138649"/>
            </criteria>
            <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.18834" test_ref="oval:org.mitre.oval:tst:138724"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8/2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:115678"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.21457" test_ref="oval:org.mitre.oval:tst:138582"/>
            </criteria>
            <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.17343" test_ref="oval:org.mitre.oval:tst:138343"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1 / 2K12 R2and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of win32k.sys is less than 6.3.9600.17796" test_ref="oval:org.mitre.oval:tst:138198"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28807" version="3" class="vulnerability">
      <metadata>
        <title>Adobe font driver remote code execution vulnerability - CVE-2015-0088 (MS15-021)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-0088" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0088"/>
        <description>Adobe Font Driver in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to execute arbitrary code via a crafted (1) web site or (2) file, aka "Adobe Font Driver Remote Code Execution Vulnerability," a different vulnerability than CVE-2015-0090, CVE-2015-0091, CVE-2015-0092, and CVE-2015-0093.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-03-16T10:01:42">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-03-17T10:44:58.583-04:00">DRAFT</status_change>
            <status_change date="2015-04-06T04:00:15.571-04:00">INTERIM</status_change>
            <status_change date="2015-04-27T04:00:24.899-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Server 2k3 and vulnerable file version">
          <criteria operator="OR" comment="2k3 (x86/x64/ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of atmfd.dll is less than 5.2.2.241" test_ref="oval:org.mitre.oval:tst:138235"/>
        </criteria>
        <criteria operator="AND" comment="Vista/2k8/Win7/2k8 R2/ Win 8/2k12/Win 8.1/2k12 R2 and vulnerable file version">
          <criteria operator="OR" comment="Vista/2k8/Win7/2k8 R2/ Win 8/2k12/Win 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of atmfd.dll is less than 5.1.2.241" test_ref="oval:org.mitre.oval:tst:137787"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28806" version="3" class="vulnerability">
      <metadata>
        <title>Microsoft Windows Kernel Bitmap handling use after free vulnerability - CVE-2015-1722 (MS15-061)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-1722" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1722"/>
        <description>Use-after-free vulnerability in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges via a crafted application, aka "Microsoft Windows Kernel Bitmap Handling Use After Free Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-16T10:41:46">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-06-18T10:24:28.704-04:00">DRAFT</status_change>
            <status_change date="2015-07-06T04:00:27.917-04:00">INTERIM</status_change>
            <status_change date="2015-07-27T04:00:36.388-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Windows Server 2k3 and vulnerable file version">
          <criteria operator="OR" comment="Either OS">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of win32k.sys is less than 5.2.3790.5640" test_ref="oval:org.mitre.oval:tst:138918"/>
        </criteria>
        <criteria operator="AND" comment="Vista / 2k8 + vulnerable file version">
          <criteria operator="OR" comment="Vista / 2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.0.6002.19399" test_ref="oval:org.mitre.oval:tst:138917"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:81723"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.0.6002.23706" test_ref="oval:org.mitre.oval:tst:139029"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / R2 + vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.18869" test_ref="oval:org.mitre.oval:tst:138921"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:81763"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.23072" test_ref="oval:org.mitre.oval:tst:138932"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8/2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.17385" test_ref="oval:org.mitre.oval:tst:138372"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:115678"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.21496" test_ref="oval:org.mitre.oval:tst:138968"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1 / 2K12 R2and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of win32k.sys is less than 6.3.9600.17837" test_ref="oval:org.mitre.oval:tst:139008"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28804" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-2390 (MS15-065)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-2390" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2390" source="CVE"/>
        <description>Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-2385, CVE-2015-2397, CVE-2015-2404, CVE-2015-2406, and CVE-2015-2422.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-07-22T13:00:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-07-23T11:16:40.950-04:00">DRAFT</status_change>
            <status_change date="2015-08-10T04:00:38.450-04:00">INTERIM</status_change>
            <status_change date="2015-08-31T04:00:08.690-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5662" test_ref="oval:org.mitre.oval:tst:140298"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21481" test_ref="oval:org.mitre.oval:tst:140959"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista / 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19421" test_ref="oval:org.mitre.oval:tst:140954"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23728" test_ref="oval:org.mitre.oval:tst:141086"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23707" test_ref="oval:org.mitre.oval:tst:141287"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19652" test_ref="oval:org.mitre.oval:tst:141242"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23707" test_ref="oval:org.mitre.oval:tst:141287"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18896" test_ref="oval:org.mitre.oval:tst:141220"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.23099" test_ref="oval:org.mitre.oval:tst:141285"/>
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.23000" test_ref="oval:org.mitre.oval:tst:138202"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16669" test_ref="oval:org.mitre.oval:tst:141203"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20784" test_ref="oval:org.mitre.oval:tst:141111"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17412" test_ref="oval:org.mitre.oval:tst:140758"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21523" test_ref="oval:org.mitre.oval:tst:141225"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17905" test_ref="oval:org.mitre.oval:tst:141110"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28803" version="3" class="vulnerability">
      <metadata>
        <title>Microsoft windows kernel memory disclosure vulnerability - CVE-2015-0077 (MS15-023)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-0077" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0077"/>
        <description>The kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 do not properly initialize function buffers, which allows local users to obtain sensitive information from kernel memory, and possibly bypass the ASLR protection mechanism, via a crafted application, aka "Microsoft Windows Kernel Memory Disclosure Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-03-16T09:23:57">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-03-17T10:55:37.910-04:00">DRAFT</status_change>
            <status_change date="2015-04-06T04:00:15.352-04:00">INTERIM</status_change>
            <status_change date="2015-04-27T04:00:24.504-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Windows Server 2k3 and vulnerable file version">
          <criteria operator="OR" comment="Either OS">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of win32k.sys is less than 5.2.3790.5561" test_ref="oval:org.mitre.oval:tst:138314"/>
        </criteria>
        <criteria operator="AND" comment="Vista / 2k8 + vulnerable file version">
          <criteria operator="OR" comment="Vista / 2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.0.6002.19327" test_ref="oval:org.mitre.oval:tst:138135"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:81723"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.0.6002.23636" test_ref="oval:org.mitre.oval:tst:138121"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / R2 + vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.18773" test_ref="oval:org.mitre.oval:tst:138032"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:81763"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.22978" test_ref="oval:org.mitre.oval:tst:138003"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8/2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.17287" test_ref="oval:org.mitre.oval:tst:138063"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:115678"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.21403" test_ref="oval:org.mitre.oval:tst:138335"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1 / 2K12 R2and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of win32k.sys is less than 6.3.9600.17694" test_ref="oval:org.mitre.oval:tst:138216"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28780" version="3" class="vulnerability">
      <metadata>
        <title>Task scheduler security feature bypass vulnerability - CVE-2015-0084 (MS15-028)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-0084" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0084"/>
        <description>The Task Scheduler in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 does not properly constrain impersonation levels, which allows local users to bypass intended restrictions on launching executable files via a crafted task, aka "Task Scheduler Security Feature Bypass Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-03-16T10:59:59">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-03-17T11:28:14.673-04:00">DRAFT</status_change>
            <status_change date="2015-04-06T04:00:14.260-04:00">INTERIM</status_change>
            <status_change date="2015-04-27T04:00:23.667-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Win 7 / R2 + vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of Ubpm.dll is less than 6.1.7601.22948" test_ref="oval:org.mitre.oval:tst:138109"/>
              <criterion comment="Check if the version of Ubpm.dll is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:138316"/>
            </criteria>
            <criterion comment="Check if the version of Ubpm.dll is less than 6.1.7601.18741" test_ref="oval:org.mitre.oval:tst:138334"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8/2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of Ubpm.dll is less than 6.2.9200.21364" test_ref="oval:org.mitre.oval:tst:137999"/>
              <criterion comment="Check if the version of Ubpm.dll is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:138439"/>
            </criteria>
            <criterion comment="Check if the version of Ubpm.dll is less than 6.2.9200.17247" test_ref="oval:org.mitre.oval:tst:138353"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1 / 2K12 R2and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of Ubpm.dll is less than 6.3.9600.17671" test_ref="oval:org.mitre.oval:tst:138035"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28771" version="3" class="vulnerability">
      <metadata>
        <title>Adobe font driver remote code execution vulnerability - CVE-2015-0092 (MS15-021)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-0092" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0092"/>
        <description>Adobe Font Driver in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to execute arbitrary code via a crafted (1) web site or (2) file, aka "Adobe Font Driver Remote Code Execution Vulnerability," a different vulnerability than CVE-2015-0088, CVE-2015-0090, CVE-2015-0091, and CVE-2015-0093.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-03-16T10:01:42">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-03-17T10:45:00.714-04:00">DRAFT</status_change>
            <status_change date="2015-04-06T04:00:13.976-04:00">INTERIM</status_change>
            <status_change date="2015-04-27T04:00:23.469-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Server 2k3 and vulnerable file version">
          <criteria operator="OR" comment="2k3 (x86/x64/ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of atmfd.dll is less than 5.2.2.241" test_ref="oval:org.mitre.oval:tst:138235"/>
        </criteria>
        <criteria operator="AND" comment="Vista/2k8/Win7/2k8 R2/ Win 8/2k12/Win 8.1/2k12 R2 and vulnerable file version">
          <criteria operator="OR" comment="Vista/2k8/Win7/2k8 R2/ Win 8/2k12/Win 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of atmfd.dll is less than 5.1.2.241" test_ref="oval:org.mitre.oval:tst:137787"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28770" version="3" class="vulnerability">
      <metadata>
        <title>Adobe font driver remote code execution vulnerability - CVE-2015-0090 (MS15-021)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-0090" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0090"/>
        <description>Adobe Font Driver in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to execute arbitrary code via a crafted (1) web site or (2) file, aka "Adobe Font Driver Remote Code Execution Vulnerability," a different vulnerability than CVE-2015-0088, CVE-2015-0091, CVE-2015-0092, and CVE-2015-0093.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-03-16T10:01:42">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-03-17T10:44:53.942-04:00">DRAFT</status_change>
            <status_change date="2015-04-06T04:00:13.784-04:00">INTERIM</status_change>
            <status_change date="2015-04-27T04:00:23.217-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Server 2k3 and vulnerable file version">
          <criteria operator="OR" comment="2k3 (x86/x64/ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of atmfd.dll is less than 5.2.2.241" test_ref="oval:org.mitre.oval:tst:138235"/>
        </criteria>
        <criteria operator="AND" comment="Vista/2k8/Win7/2k8 R2/ Win 8/2k12/Win 8.1/2k12 R2 and vulnerable file version">
          <criteria operator="OR" comment="Vista/2k8/Win7/2k8 R2/ Win 8/2k12/Win 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of atmfd.dll is less than 5.1.2.241" test_ref="oval:org.mitre.oval:tst:137787"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28769" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-1737 (MS15-056)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-1737" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1737" source="CVE"/>
        <description>Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-1731, CVE-2015-1736, and CVE-2015-1755.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-16T04:41:39">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-06-18T10:14:08.182-04:00">DRAFT</status_change>
            <status_change date="2015-07-06T04:00:26.587-04:00">INTERIM</status_change>
            <status_change date="2015-07-27T04:00:33.026-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17377" test_ref="oval:org.mitre.oval:tst:139004"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21489" test_ref="oval:org.mitre.oval:tst:138844"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17842" test_ref="oval:org.mitre.oval:tst:138937"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28767" version="4" class="vulnerability">
      <metadata>
        <title>Group Policy security feature bypass vulnerability - CVE-2015-0009 (MS15-014)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-0009" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0009"/>
        <description>The Group Policy Security Configuration policy implementation in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows man-in-the-middle attackers to disable a signing requirement and trigger a revert-to-default action by spoofing domain-controller responses, aka "Group Policy Security Feature Bypass Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-02-13T08:40:43">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-02-16T13:20:38.547-05:00">DRAFT</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:43110 - bulletins for the month of February 2015" date="2015-02-16T13:18:00.755-05:00">
              <contributor organization="SecPod Technologies">Kumarswamy S</contributor>
            </modified>
            <status_change date="2015-03-09T04:01:53.352-04:00">INTERIM</status_change>
            <status_change date="2015-03-30T04:00:29.034-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Windows Server 2k3 and vulnerable file version">
          <criteria operator="OR" comment="Either OS">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of Scesrv.dll is less than 5.2.3790.5492" test_ref="oval:org.mitre.oval:tst:137802"/>
        </criteria>
        <criteria operator="AND" comment="Vista / 2k8 + vulnerable file version">
          <criteria operator="OR" comment="Vista / 2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of Scesrv.dll is less than 6.0.6002.23558" test_ref="oval:org.mitre.oval:tst:138116"/>
              <criterion comment="Check if the version of Scesrv.dll is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:137943"/>
            </criteria>
            <criterion comment="Check if the version of Scesrv.dll is less than 6.0.6002.19251" test_ref="oval:org.mitre.oval:tst:138132"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / R2 + vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of Scesrv.dll is less than 6.1.7601.22894" test_ref="oval:org.mitre.oval:tst:137878"/>
              <criterion comment="Check if the version of Scesrv.dll is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:137512"/>
            </criteria>
            <criterion comment="Check if the version of Scesrv.dll is less than 6.1.7601.18686" test_ref="oval:org.mitre.oval:tst:138089"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8/2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of Scesrv.dll is less than 6.2.9200.21317" test_ref="oval:org.mitre.oval:tst:137843"/>
              <criterion comment="Check if the version of Scesrv.dll is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:138020"/>
            </criteria>
            <criterion comment="Check if the version of Scesrv.dll is less than 6.2.9200.17200" test_ref="oval:org.mitre.oval:tst:138096"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1 / 2K12 R2and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of Scesrv.dll is less than 6.3.9600.17552" test_ref="oval:org.mitre.oval:tst:137690"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28764" version="3" class="vulnerability">
      <metadata>
        <title>Windows create process elevation of privilege vulnerability - CVE-2015-0062 (MS15-015)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-0062" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0062"/>
        <description>Microsoft Windows Server 2008 R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allow local users to gain privileges via a crafted application that leverages incorrect impersonation handling in a process that uses the SeAssignPrimaryTokenPrivilege privilege, aka "Windows Create Process Elevation of Privilege Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-02-13T09:23:57">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-02-16T13:22:14.916-05:00">DRAFT</status_change>
            <status_change date="2015-03-09T04:01:53.140-04:00">INTERIM</status_change>
            <status_change date="2015-03-30T04:00:28.757-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Win 7 / R2 + vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of Ntoskrnl.exe is less than 6.1.7601.18715" test_ref="oval:org.mitre.oval:tst:137284"/>
            <criteria operator="AND" comment="Check for LDR range">
              <criterion comment="Check if the version of Ntoskrnl.exe is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:81000"/>
              <criterion comment="Check if the version of Ntoskrnl.exe is less than 6.1.7601.22921" test_ref="oval:org.mitre.oval:tst:137701"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8/2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of Ntoskrnl.exe is less than 6.2.9200.17231" test_ref="oval:org.mitre.oval:tst:138000"/>
            <criteria operator="AND" comment="Check for LDR range">
              <criterion comment="Check if the version of Ntoskrnl.exe is less than 6.2.9200.21347" test_ref="oval:org.mitre.oval:tst:138067"/>
              <criterion comment="Check if the version of Ntoskrnl.exe is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:137068"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1 / 2K12 R2and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of Ntoskrnl.exe is less than 6.3.9600.17630" test_ref="oval:org.mitre.oval:tst:138065"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28762" version="5" class="vulnerability">
      <metadata>
        <title>Microsoft schannel remote code execution vulnerability - CVE-2015-0003 (MS15-010)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-0003" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0003"/>
        <description>win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges or cause a denial of service (NULL pointer dereference) via a crafted application, aka "Win32k Elevation of Privilege Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-02-13T09:23:57">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-02-16T13:13:46.665-05:00">DRAFT</status_change>
            <status_change date="2015-03-09T04:01:52.789-04:00">INTERIM</status_change>
            <status_change date="2015-03-30T04:00:28.391-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:43353 - MS Bulletins - May 2015" date="2015-05-28T14:09:00.599-04:00">
              <contributor organization="SecPod Technologies">Kumarswamy S</contributor>
            </modified>
            <status_change date="2015-05-28T14:13:09.275-04:00">INTERIM</status_change>
            <status_change date="2015-06-15T04:00:26.575-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Windows Server 2k3 and vulnerable file version">
          <criteria operator="OR" comment="Either OS">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criteria operator="OR" comment="either version">
            <criterion comment="Check if the version of win32k.sys is less than 5.2.3790.5513" test_ref="oval:org.mitre.oval:tst:137893"/>
            <criterion comment="Check if the version of Schannnel.dll is less than 5.2.3790.5516" test_ref="oval:org.mitre.oval:tst:137932"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Vista / 2k8 + vulnerable file version">
          <criteria operator="OR" comment="Vista / 2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.0.6002.19279" test_ref="oval:org.mitre.oval:tst:137920"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:81723"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.0.6002.23588" test_ref="oval:org.mitre.oval:tst:138008"/>
            </criteria>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of Ksecdd.sys is less than 6.0.6002.23592" test_ref="oval:org.mitre.oval:tst:137948"/>
              <criterion comment="Check if the version of Ksecdd.sys is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:137239"/>
            </criteria>
            <criterion comment="Check if the version of Ksecdd.sys is less than 6.0.6002.19282" test_ref="oval:org.mitre.oval:tst:138056"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / R2 + vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.18713" test_ref="oval:org.mitre.oval:tst:137986"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:81763"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.22919" test_ref="oval:org.mitre.oval:tst:137933"/>
            </criteria>
            <criterion comment="Check if the version of the Cng.sys is less than 6.1.7601.18717" test_ref="oval:org.mitre.oval:tst:138087"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of the Cng.sys is less than 6.1.7601.22923" test_ref="oval:org.mitre.oval:tst:138072"/>
              <criterion comment="Check if the version of the Cng.sys is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:137664"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8/2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.17226" test_ref="oval:org.mitre.oval:tst:138100"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:115678"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.21343" test_ref="oval:org.mitre.oval:tst:137841"/>
            </criteria>
            <criterion comment="Check if the version of the Cng.sys is less than 6.2.9200.17230" test_ref="oval:org.mitre.oval:tst:137968"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of the Cng.sys is less than 6.2.9200.21347" test_ref="oval:org.mitre.oval:tst:137865"/>
              <criterion comment="Check if the version of the Cng.sys is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:137956"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1 / 2K12 R2and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of win32k.sys is less than 6.3.9600.17630" test_ref="oval:org.mitre.oval:tst:137568"/>
          <criterion comment="Check if the version of the Cng.sys is less than 6.3.9600.17633" test_ref="oval:org.mitre.oval:tst:137745"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28757" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-1622 (MS15-018)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-1622" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1622" source="CVE"/>
        <description>Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-03-16T09:23:57">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-03-17T10:36:46.514-04:00">DRAFT</status_change>
            <status_change date="2015-04-06T04:00:13.440-04:00">INTERIM</status_change>
            <status_change date="2015-04-27T04:00:22.600-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17267" test_ref="oval:org.mitre.oval:tst:138160"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21384" test_ref="oval:org.mitre.oval:tst:138199"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17690" test_ref="oval:org.mitre.oval:tst:138148"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28753" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-1689 (MS15-043)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-1689" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1689" source="CVE"/>
        <description>Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-1705.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-05-20T08:43:05">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-05-28T14:16:30.439-04:00">DRAFT</status_change>
            <status_change date="2015-06-15T04:00:26.222-04:00">INTERIM</status_change>
            <status_change date="2015-07-06T04:00:26.253-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16644" test_ref="oval:org.mitre.oval:tst:138514"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20758" test_ref="oval:org.mitre.oval:tst:138561"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17357" test_ref="oval:org.mitre.oval:tst:138213"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21470" test_ref="oval:org.mitre.oval:tst:138585"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17801" test_ref="oval:org.mitre.oval:tst:138184"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28750" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-0038 (MS15-009)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-0038" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0038" source="CVE"/>
        <description>Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-0042 and CVE-2015-0046.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-02-13T10:59:59">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-02-16T13:11:31.933-05:00">DRAFT</status_change>
            <status_change date="2015-03-09T04:01:52.534-04:00">INTERIM</status_change>
            <status_change date="2015-03-30T04:00:28.094-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16609" test_ref="oval:org.mitre.oval:tst:138073"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20725" test_ref="oval:org.mitre.oval:tst:137846"/>
            </criteria>
            <criterion comment="Check if the version of Jscript9.dll is less than 9.0.8112.16620" test_ref="oval:org.mitre.oval:tst:137873"/>
            <criteria operator="AND" comment="Jscript and LDR">
              <criterion comment="Check if the version of Jscript9.dll is less than 9.0.8112.20730" test_ref="oval:org.mitre.oval:tst:137974"/>
              <criterion comment="Check if the version of Jscript9.dll is greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:137868"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <criteria operator="AND" comment="Win 7/R2">
              <criteria operator="OR" comment="Win 7/R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17229" test_ref="oval:org.mitre.oval:tst:137987"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21345" test_ref="oval:org.mitre.oval:tst:137107"/>
                </criteria>
                <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.17241" test_ref="oval:org.mitre.oval:tst:137700"/>
                <criteria operator="AND" comment="Jscript.dll and LDR">
                  <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.21359" test_ref="oval:org.mitre.oval:tst:137021"/>
                  <criterion comment="Check if the version of Jscript9.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:137516"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 8/ 2012 R2">
              <criteria operator="OR" comment="Win 8/ 2012">
                <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
                <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
                <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17228" test_ref="oval:org.mitre.oval:tst:137876"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21345" test_ref="oval:org.mitre.oval:tst:137107"/>
                </criteria>
                <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.17241" test_ref="oval:org.mitre.oval:tst:137700"/>
                <criteria operator="AND" comment="Jscript.dll and LDR">
                  <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.21359" test_ref="oval:org.mitre.oval:tst:137021"/>
                  <criterion comment="Check if the version of Jscript9.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:137516"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/ 2k12 R2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7/ 2k8 R2/ 8.1/ 2k12 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criteria operator="OR" comment="either file">
                <criterion comment="Check if the version of Jscript9.dll is less than 11.0.9600.17640" test_ref="oval:org.mitre.oval:tst:137882"/>
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17631" test_ref="oval:org.mitre.oval:tst:137835"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28743" version="3" class="vulnerability">
      <metadata>
        <title>Win32k information disclosure vulnerability - CVE-2015-2367 (MS15-073)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-2367" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2367"/>
        <description>win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to obtain sensitive information from uninitialized kernel memory via a crafted application, aka "Win32k Information Disclosure Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-07-22T16:53:08">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-07-23T11:25:51.163-04:00">DRAFT</status_change>
            <status_change date="2015-08-10T04:00:36.176-04:00">INTERIM</status_change>
            <status_change date="2015-08-31T04:00:08.070-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Windows Server 2k3 and vulnerable file version">
          <criteria operator="OR" comment="Either OS">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of win32k.sys is less than 5.2.3790.5667" test_ref="oval:org.mitre.oval:tst:141098"/>
        </criteria>
        <criteria operator="AND" comment="Vista / 2k8 + vulnerable file version">
          <criteria operator="OR" comment="Vista / 2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.0.6002.19429" test_ref="oval:org.mitre.oval:tst:141152"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:81723"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.0.6002.23735" test_ref="oval:org.mitre.oval:tst:141262"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / R2 + vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.18906" test_ref="oval:org.mitre.oval:tst:141244"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:81763"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.23109" test_ref="oval:org.mitre.oval:tst:141301"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8/2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.17419" test_ref="oval:org.mitre.oval:tst:141068"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:115678"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.21528" test_ref="oval:org.mitre.oval:tst:141153"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1 / 2K12 R2and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of win32k.sys is less than 6.3.9600.17915" test_ref="oval:org.mitre.oval:tst:141251"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28742" version="3" class="vulnerability">
      <metadata>
        <title>Windows Journal remote code execution vulnerability - CVE-2015-1675 (MS15-045)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-1675" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1675"/>
        <description>Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allow remote attackers to execute arbitrary code via a crafted Journal file, aka "Windows Journal Remote Code Execution Vulnerability," a different vulnerability than CVE-2015-1695, CVE-2015-1696, CVE-2015-1697, CVE-2015-1698, and CVE-2015-1699.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-05-20T18:56:32">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-05-28T14:32:56.931-04:00">DRAFT</status_change>
            <status_change date="2015-06-15T04:00:25.427-04:00">INTERIM</status_change>
            <status_change date="2015-07-06T04:00:24.687-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vista / 2k8 + vulnerable file version">
          <criteria operator="OR" comment="Vista / 2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Journal.dll is less than 6.0.6002.23664" test_ref="oval:org.mitre.oval:tst:138166"/>
              <criterion comment="Check if the version of Journal.dll is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:138660"/>
            </criteria>
            <criterion comment="Check if the version of Journal.dll is less than 6.0.6002.19356" test_ref="oval:org.mitre.oval:tst:138728"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / R2 + vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Journal.dll is less than 6.1.7601.23020" test_ref="oval:org.mitre.oval:tst:138830"/>
              <criterion comment="Check if the version of Journal.dll is greater than or equal to 6.1.7601.23000" test_ref="oval:org.mitre.oval:tst:138508"/>
            </criteria>
            <criterion comment="Check if the version of Journal.dll is less than 6.1.7601.18815" test_ref="oval:org.mitre.oval:tst:138819"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8/2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Journal.dll is less than 6.2.9200.21444" test_ref="oval:org.mitre.oval:tst:138174"/>
              <criterion comment="Check if the version of Journal.dll is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:138277"/>
            </criteria>
            <criterion comment="Check if the version of Journal.dll is less than 6.2.9200.17330" test_ref="oval:org.mitre.oval:tst:138698"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1 / 2K12 R2and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of Journal.dll is less than 6.3.9600.17793" test_ref="oval:org.mitre.oval:tst:138477"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28739" version="4" class="vulnerability">
      <metadata>
        <title>.NET XML decryption denial of service vulnerability - CVE-2015-1672 (MS15-048)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows Vista</platform>
          <product>Microsoft .NET Framework 2.0</product>
          <product>Microsoft .NET Framework 3.5</product>
          <product>Microsoft .NET Framework 3.5.1</product>
          <product>Microsoft .NET Framework 4.0</product>
          <product>Microsoft .NET Framework 4.5</product>
          <product>Microsoft .NET Framework 4.5.1</product>
          <product>Microsoft .NET Framework 4.5.2</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-1672" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1672"/>
        <description>Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, and 4.5.2 allows remote attackers to cause a denial of service (recursion and performance degradation) via crafted encrypted data in an XML document, aka ".NET XML Decryption Denial of Service Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-05-20T11:54:36">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-05-28T14:35:01.777-04:00">DRAFT</status_change>
            <status_change date="2015-06-15T04:00:25.043-04:00">INTERIM</status_change>
            <status_change date="2015-07-06T04:00:24.067-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:28739 - Changed product names to represent versions consistently." date="2015-08-17T14:52:00.686-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-08-17T14:55:17.046-04:00">INTERIM</status_change>
          </dates>
          <status>INTERIM</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment=".NET 2.0 and  XP / server 2003">
          <criteria operator="OR" comment="Either OS">
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 2.0 Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6158"/>
          <criterion comment="Check if the version of System.Security.dll is less than 2.0.50727.3665" test_ref="oval:org.mitre.oval:tst:138113"/>
        </criteria>
        <criteria operator="AND" comment=".NET 2.0 and Vista / 2008">
          <criteria operator="OR" comment="Either OS">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 2.0 Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6158"/>
          <criteria operator="OR" comment="gdr and ldr range">
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of system.security.dll is less than 2.0.50727.8652" test_ref="oval:org.mitre.oval:tst:137940"/>
              <criterion comment="Check if the version of system.security.dll is greater than or equal to 2.0.50727.8600" test_ref="oval:org.mitre.oval:tst:138046"/>
            </criteria>
            <criterion comment="Check if the version of system.security.dll is less than 2.0.50727.4256" test_ref="oval:org.mitre.oval:tst:138846"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment=".NET 3.5 and Win 8 / server 2012">
          <criteria operator="OR" comment="Either OS">
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 3.5 SP1 is installed" definition_ref="oval:org.mitre.oval:def:12542"/>
          <criteria operator="OR" comment="gdr and ldr range">
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of system.security.dll is less than 2.0.50727.8652" test_ref="oval:org.mitre.oval:tst:137940"/>
              <criterion comment="Check if the version of system.security.dll is greater than or equal to 2.0.50727.8600" test_ref="oval:org.mitre.oval:tst:138046"/>
            </criteria>
            <criterion comment="Check if the version of system.security.dll is less than 2.0.50727.6426" test_ref="oval:org.mitre.oval:tst:138697"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment=".NET and Win 8.1 / 2012 R2">
          <criteria operator="OR" comment="Either OS">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 3.5 SP1 is installed" definition_ref="oval:org.mitre.oval:def:12542"/>
          <criteria operator="OR" comment="gdr and ldr range">
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of system.security.dll is less than 2.0.50727.8652" test_ref="oval:org.mitre.oval:tst:137940"/>
              <criterion comment="Check if the version of system.security.dll is greater than or equal to 2.0.50727.8600" test_ref="oval:org.mitre.oval:tst:138046"/>
            </criteria>
            <criterion comment="Check if the version of system.security.dll is less than 2.0.50727.8015" test_ref="oval:org.mitre.oval:tst:138758"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment=".NET 3.5.1 and Win 7 / Server 2008 R2">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 3.5 SP1 is installed" definition_ref="oval:org.mitre.oval:def:12542"/>
          <criteria operator="OR" comment="gdr and ldr range">
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of system.security.dll is less than 2.0.50727.8652" test_ref="oval:org.mitre.oval:tst:137940"/>
              <criterion comment="Check if the version of system.security.dll is greater than or equal to 2.0.50727.8600" test_ref="oval:org.mitre.oval:tst:138046"/>
            </criteria>
            <criterion comment="Check if the version of system.security.dll is less than 2.0.50727.5490" test_ref="oval:org.mitre.oval:tst:138559"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment=".NET 4.0">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6749"/>
          <criteria operator="OR" comment="gdr and ldr range">
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of system.security.dll is less than 4.0.30319.2056" test_ref="oval:org.mitre.oval:tst:138327"/>
              <criterion comment="Check if version of System.Security.dll is greater than or equal to 4.0.30319.2000" test_ref="oval:org.mitre.oval:tst:80978"/>
            </criteria>
            <criterion comment="Check if the version of system.security.dll is less than 4.0.30319.1031" test_ref="oval:org.mitre.oval:tst:138792"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment=".NET 4.5/4.5.1 and Win Vista / Win 7 / server 2008 / Server 2008 R2">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Either .Net 4.5 / 4.5.1 / 4.5.2 and version">
            <extend_definition comment="Microsoft .NET Framework 4.5 is installed" definition_ref="oval:org.mitre.oval:def:15925"/>
            <extend_definition comment="Microsoft .NET Framework 4.5.1 is installed" definition_ref="oval:org.mitre.oval:def:22275"/>
            <extend_definition comment="Microsoft .NET Framework 4.5.2 is installed" definition_ref="oval:org.mitre.oval:def:26546"/>
          </criteria>
          <criteria operator="OR" comment="Either file version">
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of system.security.dll is less than 4.0.30319.36288" test_ref="oval:org.mitre.oval:tst:138794"/>
              <criterion comment="Check if the version of system.security.dll is greater than or equal to 4.0.30319.36000" test_ref="oval:org.mitre.oval:tst:138076"/>
            </criteria>
            <criterion comment="Check fi the version of system.security.dll is less than 4.0.30319.34252" test_ref="oval:org.mitre.oval:tst:138631"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment=".NET and Win 8 /Server 2012">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Either .Net 4.5 / 4.5.1 / 4.5.2 and version">
            <extend_definition comment="Microsoft .NET Framework 4.5 is installed" definition_ref="oval:org.mitre.oval:def:15925"/>
            <extend_definition comment="Microsoft .NET Framework 4.5.1 is installed" definition_ref="oval:org.mitre.oval:def:22275"/>
            <extend_definition comment="Microsoft .NET Framework 4.5.2 is installed" definition_ref="oval:org.mitre.oval:def:26546"/>
          </criteria>
          <criteria operator="OR" comment="Either file version">
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of system.security.dll is less than 4.0.30319.36283" test_ref="oval:org.mitre.oval:tst:138774"/>
              <criterion comment="Check if the version of system.security.dll is greater than or equal to 4.0.30319.36000" test_ref="oval:org.mitre.oval:tst:138076"/>
            </criteria>
            <criterion comment="Check if the version of system.security.dll is less than 4.0.30319.34248" test_ref="oval:org.mitre.oval:tst:138577"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment=".NET 4.5.1 / 4.5.2 and  Win 8.1 / Server 2012 R2">
          <criteria operator="OR" comment="Either .Net 4.5.1 / 4.5.2 version">
            <extend_definition comment="Microsoft .NET Framework 4.5.1 is installed" definition_ref="oval:org.mitre.oval:def:22275"/>
            <extend_definition comment="Microsoft .NET Framework 4.5.2 is installed" definition_ref="oval:org.mitre.oval:def:26546"/>
          </criteria>
          <criteria operator="OR" comment="Either OS">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criteria operator="OR" comment="Either file version">
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of system.security.dll is less than 4.0.30319.36283" test_ref="oval:org.mitre.oval:tst:138774"/>
              <criterion comment="Check if the version of system.security.dll is greater than or equal to 4.0.30319.36000" test_ref="oval:org.mitre.oval:tst:138076"/>
            </criteria>
            <criterion comment="Check if the version of system.security.dll is less than 4.0.30319.34248" test_ref="oval:org.mitre.oval:tst:138577"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28738" version="3" class="vulnerability">
      <metadata>
        <title>Adobe font driver remote code execution vulnerability - CVE-2015-0093 (MS15-021)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-0093" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0093"/>
        <description>Adobe Font Driver in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to execute arbitrary code via a crafted (1) web site or (2) file, aka "Adobe Font Driver Remote Code Execution Vulnerability," a different vulnerability than CVE-2015-0088, CVE-2015-0090, CVE-2015-0091, and CVE-2015-0092.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-03-16T10:01:42">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-03-17T10:45:02.924-04:00">DRAFT</status_change>
            <status_change date="2015-04-06T04:00:13.071-04:00">INTERIM</status_change>
            <status_change date="2015-04-27T04:00:22.193-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Server 2k3 and vulnerable file version">
          <criteria operator="OR" comment="2k3 (x86/x64/ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of atmfd.dll is less than 5.2.2.241" test_ref="oval:org.mitre.oval:tst:138235"/>
        </criteria>
        <criteria operator="AND" comment="Vista/2k8/Win7/2k8 R2/ Win 8/2k12/Win 8.1/2k12 R2 and vulnerable file version">
          <criteria operator="OR" comment="Vista/2k8/Win7/2k8 R2/ Win 8/2k12/Win 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of atmfd.dll is less than 5.1.2.241" test_ref="oval:org.mitre.oval:tst:137787"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28737" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer elevation of privilege vulnerability - CVE-2015-0072 (MS15-018)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-0072" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0072" source="CVE"/>
        <description>Cross-site scripting (XSS) vulnerability in Microsoft Internet Explorer 9 through 11 allows remote attackers to bypass the Same Origin Policy and inject arbitrary web script or HTML via vectors involving an IFRAME element that triggers a redirect, a second IFRAME element that does not trigger a redirect, and an eval of a WindowProxy object, aka "Universal XSS (UXSS)."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-03-16T09:23:57">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-03-17T10:36:18.057-04:00">DRAFT</status_change>
            <status_change date="2015-04-06T04:00:12.812-04:00">INTERIM</status_change>
            <status_change date="2015-04-27T04:00:21.799-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16633" test_ref="oval:org.mitre.oval:tst:137971"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20747" test_ref="oval:org.mitre.oval:tst:137783"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17267" test_ref="oval:org.mitre.oval:tst:138160"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21384" test_ref="oval:org.mitre.oval:tst:138199"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17690" test_ref="oval:org.mitre.oval:tst:138148"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28732" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-0039 (MS15-009)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-0039" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0039" source="CVE"/>
        <description>Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-0027, CVE-2015-0035, CVE-2015-0052, and CVE-2015-0068.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-02-13T10:59:59">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-02-16T13:11:36.175-05:00">DRAFT</status_change>
            <status_change date="2015-03-09T04:01:52.070-04:00">INTERIM</status_change>
            <status_change date="2015-03-30T04:00:27.676-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <criteria operator="AND" comment="Win 7/R2">
              <criteria operator="OR" comment="Win 7/R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17229" test_ref="oval:org.mitre.oval:tst:137987"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21345" test_ref="oval:org.mitre.oval:tst:137107"/>
                </criteria>
                <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.17241" test_ref="oval:org.mitre.oval:tst:137700"/>
                <criteria operator="AND" comment="Jscript.dll and LDR">
                  <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.21359" test_ref="oval:org.mitre.oval:tst:137021"/>
                  <criterion comment="Check if the version of Jscript9.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:137516"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 8/ 2012 R2">
              <criteria operator="OR" comment="Win 8/ 2012">
                <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
                <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
                <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17228" test_ref="oval:org.mitre.oval:tst:137876"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21345" test_ref="oval:org.mitre.oval:tst:137107"/>
                </criteria>
                <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.17241" test_ref="oval:org.mitre.oval:tst:137700"/>
                <criteria operator="AND" comment="Jscript.dll and LDR">
                  <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.21359" test_ref="oval:org.mitre.oval:tst:137021"/>
                  <criterion comment="Check if the version of Jscript9.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:137516"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/ 2k12 R2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7/ 2k8 R2/ 8.1/ 2k12 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criteria operator="OR" comment="either file">
                <criterion comment="Check if the version of Jscript9.dll is less than 11.0.9600.17640" test_ref="oval:org.mitre.oval:tst:137882"/>
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17631" test_ref="oval:org.mitre.oval:tst:137835"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28731" version="5" class="vulnerability">
      <metadata>
        <title>TIFF Processing information disclosure vulnerability - CVE-2015-0061 (MS15-016)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Vista</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-0061" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0061"/>
        <description>Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 do not properly initialize memory for TIFF images, which allows remote attackers to obtain sensitive information from process memory via a crafted image file, aka "TIFF Processing Information Disclosure Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-02-13T09:23:57">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-02-16T13:23:35.449-05:00">DRAFT</status_change>
            <status_change date="2015-03-09T04:01:51.816-04:00">INTERIM</status_change>
            <status_change date="2015-03-30T04:00:27.392-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:28731 - fixed check for Windowscodecs.ddl version" date="2015-04-15T12:25:00.421-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2015-04-15T12:28:01.420-04:00">INTERIM</status_change>
            <status_change date="2015-05-04T04:00:18.142-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Check for Windows Server 2003 x86/x64 and vulnerable file version">
          <criteria operator="OR" comment="Check for Windows Server 2003 x86/x64 or Windows XP x86">
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of gdiplus.dll is less than 5.2.6002.23588" test_ref="oval:org.mitre.oval:tst:137169"/>
        </criteria>
        <criteria operator="AND" comment="Vista / 2k8 + vulnerable file version">
          <criteria operator="OR" comment="Vista / 2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="Check for LDR/GDR">
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of windowscodecs.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:135896"/>
              <criterion comment="Check if the version Windowscodecs.dll of is less than 7.0.6002.23591" test_ref="oval:org.mitre.oval:tst:138070"/>
            </criteria>
            <criterion comment="Check if the version Windowscodecs.dll of is less than 7.0.6002.19281" test_ref="oval:org.mitre.oval:tst:138090"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / R2 + vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="Windowscodecs.dll is 6.1 or 6.2">
            <criteria comment="6.2">
              <criterion comment="Check if the version Windowscodecs.dll of is greater than 6.2" test_ref="oval:org.mitre.oval:tst:137662"/>
              <criteria operator="OR" comment="Check for LDR/GDR">
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of windowscodecs.dll is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:135899"/>
                  <criterion comment="Check if the version Windowscodecs.dll of is less than 6.2.9200.21343" test_ref="oval:org.mitre.oval:tst:137952"/>
                </criteria>
                <criterion comment="Check if the version Windowscodecs.dll of is less than 6.2.9200.17226" test_ref="oval:org.mitre.oval:tst:137222"/>
              </criteria>
            </criteria>
            <criteria comment="6.1">
              <criterion comment="Check if the version Windowscodecs.dll of is less than 6.2" test_ref="oval:org.mitre.oval:tst:138040"/>
              <criteria operator="OR" comment="either file versions">
                <criteria operator="AND" comment="ldr range">
                  <criterion comment="Check if the version of Windowscodecs.dll is less than 6.1.7601.22922" test_ref="oval:org.mitre.oval:tst:138081"/>
                  <criterion comment="Check if the version of Windowscodecs.dll is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:137874"/>
                </criteria>
                <criterion comment="Check if the version of Windowscodecs.dll is less than 6.1.7601.18716" test_ref="oval:org.mitre.oval:tst:137954"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8/2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of windowscodecs.dll is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:135899"/>
              <criterion comment="Check if the version Windowscodecs.dll of is less than 6.2.9200.21345" test_ref="oval:org.mitre.oval:tst:138119"/>
            </criteria>
            <criterion comment="Check if the version Windowscodecs.dll of is less than 6.2.9200.17228" test_ref="oval:org.mitre.oval:tst:137975"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1 / 2K12 R2and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version Windowscodecs.dll of is less than 6.3.9600.17631" test_ref="oval:org.mitre.oval:tst:137585"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28730" version="3" class="vulnerability">
      <metadata>
        <title>Adobe font driver denial of service vulnerability - CVE-2015-0074 (MS15-021)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-0074" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0074"/>
        <description>Adobe Font Driver in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 does not properly allocate memory, which allows remote attackers to cause a denial of service via a crafted (1) web site or (2) file, aka "Adobe Font Driver Denial of Service Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-03-16T10:01:42">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-03-17T10:44:46.568-04:00">DRAFT</status_change>
            <status_change date="2015-04-06T04:00:12.601-04:00">INTERIM</status_change>
            <status_change date="2015-04-27T04:00:21.431-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Server 2k3 and vulnerable file version">
          <criteria operator="OR" comment="2k3 (x86/x64/ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of atmfd.dll is less than 5.2.2.241" test_ref="oval:org.mitre.oval:tst:138235"/>
        </criteria>
        <criteria operator="AND" comment="Vista/2k8/Win7/2k8 R2/ Win 8/2k12/Win 8.1/2k12 R2 and vulnerable file version">
          <criteria operator="OR" comment="Vista/2k8/Win7/2k8 R2/ Win 8/2k12/Win 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of atmfd.dll is less than 5.1.2.241" test_ref="oval:org.mitre.oval:tst:137787"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28728" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer elevation of privilege vulnerability - CVE-2015-0055 (MS15-009)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-0055" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0055" source="CVE"/>
        <description>Microsoft Internet Explorer 10 and 11 allows remote attackers to gain privileges via a crafted web site, aka "Internet Explorer Elevation of Privilege Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-02-13T10:59:59">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-02-16T13:11:43.195-05:00">DRAFT</status_change>
            <status_change date="2015-03-09T04:01:51.473-04:00">INTERIM</status_change>
            <status_change date="2015-03-30T04:00:26.969-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <criteria operator="AND" comment="Win 7/R2">
              <criteria operator="OR" comment="Win 7/R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17229" test_ref="oval:org.mitre.oval:tst:137987"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21345" test_ref="oval:org.mitre.oval:tst:137107"/>
                </criteria>
                <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.17241" test_ref="oval:org.mitre.oval:tst:137700"/>
                <criteria operator="AND" comment="Jscript.dll and LDR">
                  <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.21359" test_ref="oval:org.mitre.oval:tst:137021"/>
                  <criterion comment="Check if the version of Jscript9.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:137516"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 8/ 2012 R2">
              <criteria operator="OR" comment="Win 8/ 2012">
                <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
                <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
                <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17228" test_ref="oval:org.mitre.oval:tst:137876"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21345" test_ref="oval:org.mitre.oval:tst:137107"/>
                </criteria>
                <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.17241" test_ref="oval:org.mitre.oval:tst:137700"/>
                <criteria operator="AND" comment="Jscript.dll and LDR">
                  <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.21359" test_ref="oval:org.mitre.oval:tst:137021"/>
                  <criterion comment="Check if the version of Jscript9.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:137516"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/ 2k12 R2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7/ 2k8 R2/ 8.1/ 2k12 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criteria operator="OR" comment="either file">
                <criterion comment="Check if the version of Jscript9.dll is less than 11.0.9600.17640" test_ref="oval:org.mitre.oval:tst:137882"/>
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17631" test_ref="oval:org.mitre.oval:tst:137835"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28718" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-0022 (MS15-009)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
          <product>Microsoft Internet Explorer 6</product>
        </affected>
        <reference ref_id="CVE-2015-0022" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0022" source="CVE"/>
        <description>Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-0017, CVE-2015-0020, CVE-2015-0026, CVE-2015-0030, CVE-2015-0031, CVE-2015-0036, and CVE-2015-0041.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-02-13T10:59:59">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-02-16T13:12:07.271-05:00">DRAFT</status_change>
            <status_change date="2015-03-09T04:01:51.071-04:00">INTERIM</status_change>
            <status_change date="2015-03-30T04:00:26.532-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5508" test_ref="oval:org.mitre.oval:tst:137925"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21432" test_ref="oval:org.mitre.oval:tst:138027"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista / 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19281" test_ref="oval:org.mitre.oval:tst:138002"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23590" test_ref="oval:org.mitre.oval:tst:137924"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23644" test_ref="oval:org.mitre.oval:tst:137686"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19600" test_ref="oval:org.mitre.oval:tst:137706"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23655" test_ref="oval:org.mitre.oval:tst:137677"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18715" test_ref="oval:org.mitre.oval:tst:138039"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22921" test_ref="oval:org.mitre.oval:tst:137991"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16609" test_ref="oval:org.mitre.oval:tst:138073"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20725" test_ref="oval:org.mitre.oval:tst:137846"/>
            </criteria>
            <criterion comment="Check if the version of Jscript9.dll is less than 9.0.8112.16620" test_ref="oval:org.mitre.oval:tst:137873"/>
            <criteria operator="AND" comment="Jscript and LDR">
              <criterion comment="Check if the version of Jscript9.dll is less than 9.0.8112.20730" test_ref="oval:org.mitre.oval:tst:137974"/>
              <criterion comment="Check if the version of Jscript9.dll is greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:137868"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <criteria operator="AND" comment="Win 7/R2">
              <criteria operator="OR" comment="Win 7/R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17229" test_ref="oval:org.mitre.oval:tst:137987"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21345" test_ref="oval:org.mitre.oval:tst:137107"/>
                </criteria>
                <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.17241" test_ref="oval:org.mitre.oval:tst:137700"/>
                <criteria operator="AND" comment="Jscript.dll and LDR">
                  <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.21359" test_ref="oval:org.mitre.oval:tst:137021"/>
                  <criterion comment="Check if the version of Jscript9.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:137516"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 8/ 2012 R2">
              <criteria operator="OR" comment="Win 8/ 2012">
                <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
                <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
                <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17228" test_ref="oval:org.mitre.oval:tst:137876"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21345" test_ref="oval:org.mitre.oval:tst:137107"/>
                </criteria>
                <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.17241" test_ref="oval:org.mitre.oval:tst:137700"/>
                <criteria operator="AND" comment="Jscript.dll and LDR">
                  <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.21359" test_ref="oval:org.mitre.oval:tst:137021"/>
                  <criterion comment="Check if the version of Jscript9.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:137516"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/ 2k12 R2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7/ 2k8 R2/ 8.1/ 2k12 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criteria operator="OR" comment="either file">
                <criterion comment="Check if the version of Jscript9.dll is less than 11.0.9600.17640" test_ref="oval:org.mitre.oval:tst:137882"/>
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17631" test_ref="oval:org.mitre.oval:tst:137835"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28717" version="3" class="vulnerability">
      <metadata>
        <title>Directory Traversal elevation of privilege vulnerability - CVE-2015-0016 (MS15-004)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Vista</platform>
          <product>Microsoft Windows Remote Desktop Connection 7.0</product>
          <product>Microsoft Windows Remote Desktop Connection 8.0</product>
          <product>Microsoft Windows Remote Desktop Connection 8.1</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-0016" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0016"/>
        <description>Directory traversal vulnerability in the TS WebProxy (aka TSWbPrxy) component in Microsoft Windows Vista SP2, Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to gain privileges via a crafted pathname in an executable file, as demonstrated by a transition from Low Integrity to Medium Integrity, aka "Directory Traversal Elevation of Privilege Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-01-16T08:40:43">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-01-16T19:19:16.598-05:00">DRAFT</status_change>
            <status_change date="2015-02-02T04:00:37.791-05:00">INTERIM</status_change>
            <status_change date="2015-02-23T04:01:33.966-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vista / Remote Desktop 7.0 / vulnerable file version">
          <criteria operator="OR" comment="Vista / 2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criteria operator="AND" comment="Remote Desktop 7.0 and Check for LDR">
              <criterion comment="Check if the version of Tswbprxy.exe is less than 6.1.7600.17715" test_ref="oval:org.mitre.oval:tst:137087"/>
              <criterion comment="Check if the version of Tswbprxy.exe is greater than or equal to 6.1.7600.00000" test_ref="oval:org.mitre.oval:tst:136870"/>
            </criteria>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Tswbprxy.exe is greater than or equal to 6.1.7600.21000" test_ref="oval:org.mitre.oval:tst:137555"/>
              <criterion comment="Check if the version of Tswbprxy.exe is less than 6.1.7600.21909" test_ref="oval:org.mitre.oval:tst:137523"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / R2 + vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of Tswbprxy.exe is less than 6.1.7601.18699" test_ref="oval:org.mitre.oval:tst:137471"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Tswbprxy.exe is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:137404"/>
              <criterion comment="Check if the version of Tswbprxy.exe is less than 6.1.7601.22907" test_ref="oval:org.mitre.oval:tst:137490"/>
            </criteria>
            <criteria operator="AND" comment="Remote Desktop 8.0 and vulnerable version">
              <criterion comment="Check if the version of Tswbprxy.exe is less than 6.2.9200.17212" test_ref="oval:org.mitre.oval:tst:137630"/>
              <criterion comment="Check if the version of Tswbprxy.exe is greater than or equal to 6.2.9200.00000" test_ref="oval:org.mitre.oval:tst:137557"/>
            </criteria>
            <criteria operator="AND" comment="Remote Desktop 8.0 and Check for LDR">
              <criterion comment="Check if the version of Tswbprxy.exe is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:136901"/>
              <criterion comment="Check if the version of Tswbprxy.exe is less than 6.2.9200.21329" test_ref="oval:org.mitre.oval:tst:136668"/>
            </criteria>
            <criteria operator="AND" comment="Remote Desktop 8.1 and vulnerable version">
              <criterion comment="Check if the version of Tswbprxy.exe is less than 6.3.9600.17553" test_ref="oval:org.mitre.oval:tst:136858"/>
              <criterion comment="Check if the version of Tswbprxy.exe is greater than or equal to 6.3.9600.00000" test_ref="oval:org.mitre.oval:tst:137545"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="2008 R2 IA64 + vulnerable file version">
          <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of Tswbprxy.exe is less than 6.1.7601.18699" test_ref="oval:org.mitre.oval:tst:137471"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Tswbprxy.exe is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:137404"/>
              <criterion comment="Check if the version of Tswbprxy.exe is less than 6.1.7601.22907" test_ref="oval:org.mitre.oval:tst:137490"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8/2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of Tswbprxy.exe is less than 6.2.9200.17213" test_ref="oval:org.mitre.oval:tst:137622"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Tswbprxy.exe is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:136901"/>
              <criterion comment="Check if the version of Tswbprxy.exe is less than 6.2.9200.21329" test_ref="oval:org.mitre.oval:tst:136668"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1 / 2K12 R2and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of Tswbprxy.exe is less than 6.3.9600.17555" test_ref="oval:org.mitre.oval:tst:137058"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28714" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-0025 (MS15-009)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <product>Microsoft Internet Explorer 10</product>
        </affected>
        <reference ref_id="CVE-2015-0025" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0025" source="CVE"/>
        <description>Microsoft Internet Explorer 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-0023.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-02-13T10:59:59">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-02-16T13:11:11.825-05:00">DRAFT</status_change>
            <status_change date="2015-03-09T04:01:50.861-04:00">INTERIM</status_change>
            <status_change date="2015-03-30T04:00:26.270-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
        <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
          <criteria operator="AND" comment="Win 7/R2">
            <criteria operator="OR" comment="Win 7/R2">
              <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
              <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
              <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            </criteria>
            <criteria operator="OR" comment="Check for vulnerable versions">
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17229" test_ref="oval:org.mitre.oval:tst:137987"/>
              <criteria operator="AND" comment="Check for LDR">
                <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
                <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21345" test_ref="oval:org.mitre.oval:tst:137107"/>
              </criteria>
              <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.17241" test_ref="oval:org.mitre.oval:tst:137700"/>
              <criteria operator="AND" comment="Jscript.dll and LDR">
                <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.21359" test_ref="oval:org.mitre.oval:tst:137021"/>
                <criterion comment="Check if the version of Jscript9.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:137516"/>
              </criteria>
            </criteria>
          </criteria>
          <criteria operator="AND" comment="Win 8/ 2012 R2">
            <criteria operator="OR" comment="Win 8/ 2012">
              <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
              <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
              <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
            </criteria>
            <criteria operator="OR" comment="Check for vulnerable versions">
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17228" test_ref="oval:org.mitre.oval:tst:137876"/>
              <criteria operator="AND" comment="Check for LDR">
                <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
                <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21345" test_ref="oval:org.mitre.oval:tst:137107"/>
              </criteria>
              <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.17241" test_ref="oval:org.mitre.oval:tst:137700"/>
              <criteria operator="AND" comment="Jscript.dll and LDR">
                <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.21359" test_ref="oval:org.mitre.oval:tst:137021"/>
                <criterion comment="Check if the version of Jscript9.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:137516"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28711" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-0020 (MS15-009)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
          <product>Microsoft Internet Explorer 6</product>
        </affected>
        <reference ref_id="CVE-2015-0020" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0020" source="CVE"/>
        <description>Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-0017, CVE-2015-0022, CVE-2015-0026, CVE-2015-0030, CVE-2015-0031, CVE-2015-0036, and CVE-2015-0041.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-02-13T10:59:59">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-02-16T13:11:08.991-05:00">DRAFT</status_change>
            <status_change date="2015-03-09T04:01:50.416-04:00">INTERIM</status_change>
            <status_change date="2015-03-30T04:00:25.919-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5508" test_ref="oval:org.mitre.oval:tst:137925"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21432" test_ref="oval:org.mitre.oval:tst:138027"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista / 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19281" test_ref="oval:org.mitre.oval:tst:138002"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23590" test_ref="oval:org.mitre.oval:tst:137924"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23644" test_ref="oval:org.mitre.oval:tst:137686"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19600" test_ref="oval:org.mitre.oval:tst:137706"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23655" test_ref="oval:org.mitre.oval:tst:137677"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18715" test_ref="oval:org.mitre.oval:tst:138039"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22921" test_ref="oval:org.mitre.oval:tst:137991"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16609" test_ref="oval:org.mitre.oval:tst:138073"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20725" test_ref="oval:org.mitre.oval:tst:137846"/>
            </criteria>
            <criterion comment="Check if the version of Jscript9.dll is less than 9.0.8112.16620" test_ref="oval:org.mitre.oval:tst:137873"/>
            <criteria operator="AND" comment="Jscript and LDR">
              <criterion comment="Check if the version of Jscript9.dll is less than 9.0.8112.20730" test_ref="oval:org.mitre.oval:tst:137974"/>
              <criterion comment="Check if the version of Jscript9.dll is greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:137868"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <criteria operator="AND" comment="Win 7/R2">
              <criteria operator="OR" comment="Win 7/R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17229" test_ref="oval:org.mitre.oval:tst:137987"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21345" test_ref="oval:org.mitre.oval:tst:137107"/>
                </criteria>
                <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.17241" test_ref="oval:org.mitre.oval:tst:137700"/>
                <criteria operator="AND" comment="Jscript.dll and LDR">
                  <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.21359" test_ref="oval:org.mitre.oval:tst:137021"/>
                  <criterion comment="Check if the version of Jscript9.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:137516"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 8/ 2012 R2">
              <criteria operator="OR" comment="Win 8/ 2012">
                <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
                <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
                <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17228" test_ref="oval:org.mitre.oval:tst:137876"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21345" test_ref="oval:org.mitre.oval:tst:137107"/>
                </criteria>
                <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.17241" test_ref="oval:org.mitre.oval:tst:137700"/>
                <criteria operator="AND" comment="Jscript.dll and LDR">
                  <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.21359" test_ref="oval:org.mitre.oval:tst:137021"/>
                  <criterion comment="Check if the version of Jscript9.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:137516"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/ 2k12 R2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7/ 2k8 R2/ 8.1/ 2k12 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criteria operator="OR" comment="either file">
                <criterion comment="Check if the version of Jscript9.dll is less than 11.0.9600.17640" test_ref="oval:org.mitre.oval:tst:137882"/>
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17631" test_ref="oval:org.mitre.oval:tst:137835"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28710" version="3" class="vulnerability">
      <metadata>
        <title>Windows Journal remote code execution vulnerability - CVE-2015-1696 (MS15-045)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-1696" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1696"/>
        <description>Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allow remote attackers to execute arbitrary code via a crafted Journal file, aka "Windows Journal Remote Code Execution Vulnerability," a different vulnerability than CVE-2015-1675, CVE-2015-1695, CVE-2015-1697, CVE-2015-1698, and CVE-2015-1699.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-05-20T18:56:32">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-05-28T14:32:52.133-04:00">DRAFT</status_change>
            <status_change date="2015-06-15T04:00:24.609-04:00">INTERIM</status_change>
            <status_change date="2015-07-06T04:00:23.296-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vista / 2k8 + vulnerable file version">
          <criteria operator="OR" comment="Vista / 2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Journal.dll is less than 6.0.6002.23664" test_ref="oval:org.mitre.oval:tst:138166"/>
              <criterion comment="Check if the version of Journal.dll is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:138660"/>
            </criteria>
            <criterion comment="Check if the version of Journal.dll is less than 6.0.6002.19356" test_ref="oval:org.mitre.oval:tst:138728"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / R2 + vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Journal.dll is less than 6.1.7601.23020" test_ref="oval:org.mitre.oval:tst:138830"/>
              <criterion comment="Check if the version of Journal.dll is greater than or equal to 6.1.7601.23000" test_ref="oval:org.mitre.oval:tst:138508"/>
            </criteria>
            <criterion comment="Check if the version of Journal.dll is less than 6.1.7601.18815" test_ref="oval:org.mitre.oval:tst:138819"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8/2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Journal.dll is less than 6.2.9200.21444" test_ref="oval:org.mitre.oval:tst:138174"/>
              <criterion comment="Check if the version of Journal.dll is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:138277"/>
            </criteria>
            <criterion comment="Check if the version of Journal.dll is less than 6.2.9200.17330" test_ref="oval:org.mitre.oval:tst:138698"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1 / 2K12 R2and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of Journal.dll is less than 6.3.9600.17793" test_ref="oval:org.mitre.oval:tst:138477"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28708" version="3" class="vulnerability">
      <metadata>
        <title>Graphics component EOP vulnerability - CVE-2015-2364 (MS15-072)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows Vista</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-2364" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2364"/>
        <description>The graphics component in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges via a crafted application that leverages an incorrect bitmap conversion, aka "Graphics Component EOP Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-07-22T20:35:28">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-07-23T11:24:06.820-04:00">DRAFT</status_change>
            <status_change date="2015-08-10T04:00:35.282-04:00">INTERIM</status_change>
            <status_change date="2015-08-31T04:00:07.231-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Server 2003 vulnerable version">
          <criteria operator="OR" comment="Server (2003 - x86/x64/ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of gdi32.dll is less than 5.2.3790.5661" test_ref="oval:org.mitre.oval:tst:140966"/>
        </criteria>
        <criteria operator="AND" comment="Vista/2K8 and vulnerable file version">
          <criteria operator="OR" comment="Vista/2k8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of gdi32.dll is less than 6.0.6002.19421" test_ref="oval:org.mitre.oval:tst:141236"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if version of gdi32.dll is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:87308"/>
              <criterion comment="Check if the version of gdi32.dll is less than 6.0.6002.23728" test_ref="oval:org.mitre.oval:tst:140635"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / R2 and vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of gdi32.dll is less than 6.1.7601.18898" test_ref="oval:org.mitre.oval:tst:141266"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if version of gdi32.dll is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:87215"/>
              <criterion comment="Check if the version of gdi32.dll is less than 6.1.7601.23100" test_ref="oval:org.mitre.oval:tst:141108"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8/2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of gdi32.dll is less than 6.2.9200.17410" test_ref="oval:org.mitre.oval:tst:141167"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of gdi32.dll is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:114810"/>
              <criterion comment="Check if the version of gdi32.dll is less than 6.2.9200.21521" test_ref="oval:org.mitre.oval:tst:141249"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Windows 8.1/ 2k12 R2 and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of gdi32.dll is less than 6.3.9600.17902" test_ref="oval:org.mitre.oval:tst:141114"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28704" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-1657 (MS15-032)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-1657" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1657" source="CVE"/>
        <description>Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-04-21T10:59:59">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-04-24T09:24:22.070-04:00">DRAFT</status_change>
            <status_change date="2015-05-11T04:00:18.550-04:00">INTERIM</status_change>
            <status_change date="2015-06-01T04:00:19.434-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16636" test_ref="oval:org.mitre.oval:tst:138537"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20750" test_ref="oval:org.mitre.oval:tst:137976"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17296" test_ref="oval:org.mitre.oval:tst:138031"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21413" test_ref="oval:org.mitre.oval:tst:138588"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17728" test_ref="oval:org.mitre.oval:tst:138275"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28700" version="3" class="vulnerability">
      <metadata>
        <title>Group Policy remote code execution vulnerability - CVE-2015-0008 (MS15-011)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-0008" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0008"/>
        <description>The UNC implementation in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 does not include authentication from the server to the client, which allows remote attackers to execute arbitrary code by making crafted data available on a UNC share, as demonstrated by Group Policy data from a spoofed domain controller, aka "Group Policy Remote Code Execution Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-02-13T09:23:57">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-02-16T13:15:28.177-05:00">DRAFT</status_change>
            <status_change date="2015-03-09T04:01:50.064-04:00">INTERIM</status_change>
            <status_change date="2015-03-30T04:00:25.706-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
        <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
        <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
        <criteria operator="AND" comment="Vista / 2k8 and vulnerable version">
          <criteria operator="OR" comment="Vista (x86/x64) / 2k8 (x86/x64/ia64)">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of Ntoskrnl.exe is less than 6.0.6002.19279" test_ref="oval:org.mitre.oval:tst:137567"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Ntoskrnl.exe is less than 6.0.6002.23588" test_ref="oval:org.mitre.oval:tst:137915"/>
              <criterion comment="Check if the version of Ntoskrnl.exe is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80719"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / R2 + vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criteria operator="AND" comment="Check for LDR range">
              <criterion comment="Check if the version of Gpsvc.dll is less than 6.1.7601.22917" test_ref="oval:org.mitre.oval:tst:137883"/>
              <criterion comment="Check if the version of Gpsvc.dll is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:137655"/>
            </criteria>
            <criterion comment="Check if the version of Gpsvc.dll is less than 6.1.7601.18711" test_ref="oval:org.mitre.oval:tst:137989"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8/2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criteria operator="AND" comment="Check for LDR range">
              <criterion comment="Check if the version of Gpsvc.dll is less than 6.2.9200.21339" test_ref="oval:org.mitre.oval:tst:137798"/>
              <criterion comment="Check if the version of Gpsvc.dll is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:137613"/>
            </criteria>
            <criterion comment="Check if the version of Gpsvc.dll is less than 6.2.9200.17225" test_ref="oval:org.mitre.oval:tst:137951"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1 / 2K12 R2and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of Gpsvc.dll is less than 6.3.9600.17630" test_ref="oval:org.mitre.oval:tst:138043"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28699" version="4" class="vulnerability">
      <metadata>
        <title>Windows Kernel security feature bypass vulnerability - CVE-2015-1674 (MS15-052)</title>
        <affected family="windows">
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-1674" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1674"/>
        <description>The kernel in Microsoft Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 does not properly validate an unspecified address, which allows local users to bypass the KASLR protection mechanism, and consequently discover the cng.sys base address, via a crafted application, aka "Windows Kernel Security Feature Bypass Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-05-20T18:56:32">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-05-28T14:13:07.576-04:00">DRAFT</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:43353 - MS Bulletins - May 2015" date="2015-05-28T14:09:00.599-04:00">
              <contributor organization="SecPod Technologies">Kumarswamy S</contributor>
            </modified>
            <status_change date="2015-06-15T04:00:24.453-04:00">INTERIM</status_change>
            <status_change date="2015-07-06T04:00:22.838-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Win 8/2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of cng.sys is less than 6.2.9200.17343" test_ref="oval:org.mitre.oval:tst:138613"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of the Cng.sys is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:137956"/>
              <criterion comment="Check if the version of cng.sys is less than 6.2.9200.21456" test_ref="oval:org.mitre.oval:tst:138247"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1 / 2K12 R2and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of cng.sys is less than 6.3.9600.17785" test_ref="oval:org.mitre.oval:tst:138345"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28695" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-0049 (MS15-009)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 10</product>
        </affected>
        <reference ref_id="CVE-2015-0049" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0049" source="CVE"/>
        <description>Microsoft Internet Explorer 8 and 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-02-13T10:59:59">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-02-16T13:10:54.028-05:00">DRAFT</status_change>
            <status_change date="2015-03-09T04:01:49.793-04:00">INTERIM</status_change>
            <status_change date="2015-03-30T04:00:25.476-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23644" test_ref="oval:org.mitre.oval:tst:137686"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19600" test_ref="oval:org.mitre.oval:tst:137706"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23655" test_ref="oval:org.mitre.oval:tst:137677"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18715" test_ref="oval:org.mitre.oval:tst:138039"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22921" test_ref="oval:org.mitre.oval:tst:137991"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <criteria operator="AND" comment="Win 7/R2">
              <criteria operator="OR" comment="Win 7/R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17229" test_ref="oval:org.mitre.oval:tst:137987"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21345" test_ref="oval:org.mitre.oval:tst:137107"/>
                </criteria>
                <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.17241" test_ref="oval:org.mitre.oval:tst:137700"/>
                <criteria operator="AND" comment="Jscript.dll and LDR">
                  <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.21359" test_ref="oval:org.mitre.oval:tst:137021"/>
                  <criterion comment="Check if the version of Jscript9.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:137516"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 8/ 2012 R2">
              <criteria operator="OR" comment="Win 8/ 2012">
                <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
                <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
                <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17228" test_ref="oval:org.mitre.oval:tst:137876"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21345" test_ref="oval:org.mitre.oval:tst:137107"/>
                </criteria>
                <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.17241" test_ref="oval:org.mitre.oval:tst:137700"/>
                <criteria operator="AND" comment="Jscript.dll and LDR">
                  <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.21359" test_ref="oval:org.mitre.oval:tst:137021"/>
                  <criterion comment="Check if the version of Jscript9.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:137516"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28694" version="4" class="vulnerability" deprecated="true">
      <metadata>
        <title>DEPRECATED: WTS remote code execution vulnerability - CVE-2015-0081 (MS15-020)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-0081" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0081"/>
        <description>Windows Text Services (WTS) in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to execute arbitrary code via a crafted (1) web site or (2) file, aka "WTS Remote Code Execution Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-03-16T12:40:27">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-03-17T10:40:13.969-04:00">DRAFT</status_change>
            <status_change date="2015-04-06T04:00:12.328-04:00">INTERIM</status_change>
            <status_change date="2015-04-27T04:00:21.040-04:00">ACCEPTED</status_change>
            <modified comment="Duplicate of 27987" date="2015-05-06T14:09:19.017-04:00">
              <contributor organization="baramundi software">Richard Helbing</contributor>
            </modified>
            <status_change date="2015-05-06T14:09:19.017-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Windows 2003 and vulnerable file versions">
          <criteria operator="OR" comment="Win 2k3 (x86/x64/ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of msctf.dll is less than 5.2.3790.5528" test_ref="oval:org.mitre.oval:tst:138239"/>
        </criteria>
        <criteria operator="AND" comment="Vista /2k8 and vulnerable file versions">
          <criteria operator="OR" comment="Vista / 2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of msctf.dll is less than 6.0.6002.19296" test_ref="oval:org.mitre.oval:tst:138034"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of msctf.dll is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:138111"/>
              <criterion comment="Check if the version of msctf.dll is less than 6.0.6002.23606" test_ref="oval:org.mitre.oval:tst:137872"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 /2k8 R2 and vulnerable file versions">
          <criteria operator="OR" comment="Win 7 / 2k8 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of msctf.dll is less than 6.1.7601.18731" test_ref="oval:org.mitre.oval:tst:138101"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of msctf.dll is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:138359"/>
              <criterion comment="Check if the version of msctf.dll is less than 6.1.7601.22937" test_ref="oval:org.mitre.oval:tst:138352"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8 /2k12 and vulnerable file versions">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of msctf.dll is less than 6.2.9200.17243" test_ref="oval:org.mitre.oval:tst:138103"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of msctf.dll is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:138024"/>
              <criterion comment="Check if the version of msctf.dll is less than 6.2.9200.21361" test_ref="oval:org.mitre.oval:tst:138146"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1 /2k12 R2 and vulnerable file versions">
          <criteria operator="OR" comment="Win 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version msctf.dll is less than 6.3.9600.17664" test_ref="oval:org.mitre.oval:tst:138158"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28692" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer elevation of privilege vulnerability - CVE-2015-1703 (MS15-043)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-1703" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1703" source="CVE"/>
        <description>Microsoft Internet Explorer 6 through 11 allows remote attackers to gain privileges via a crafted web site, aka "Internet Explorer Elevation of Privilege Vulnerability," a different vulnerability than CVE-2015-1704.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-05-20T08:43:05">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-05-28T14:16:27.260-04:00">DRAFT</status_change>
            <status_change date="2015-06-15T04:00:23.965-04:00">INTERIM</status_change>
            <status_change date="2015-07-06T04:00:22.022-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5602" test_ref="oval:org.mitre.oval:tst:138124"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21455" test_ref="oval:org.mitre.oval:tst:138315"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista / 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19367" test_ref="oval:org.mitre.oval:tst:137942"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23675" test_ref="oval:org.mitre.oval:tst:138544"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23676" test_ref="oval:org.mitre.oval:tst:138485"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19621" test_ref="oval:org.mitre.oval:tst:138412"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23676" test_ref="oval:org.mitre.oval:tst:138485"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18835" test_ref="oval:org.mitre.oval:tst:138592"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.23038" test_ref="oval:org.mitre.oval:tst:137853"/>
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.23000" test_ref="oval:org.mitre.oval:tst:138202"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16644" test_ref="oval:org.mitre.oval:tst:138514"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20758" test_ref="oval:org.mitre.oval:tst:138561"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17357" test_ref="oval:org.mitre.oval:tst:138213"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21470" test_ref="oval:org.mitre.oval:tst:138585"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17801" test_ref="oval:org.mitre.oval:tst:138184"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28689" version="5" class="vulnerability">
      <metadata>
        <title>Win32k elevation of privilege vulnerability - CVE-2015-0057 (MS15-010)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-0057" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0057"/>
        <description>win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-02-13T09:23:57">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-02-16T13:13:48.608-05:00">DRAFT</status_change>
            <status_change date="2015-03-09T04:01:49.214-04:00">INTERIM</status_change>
            <status_change date="2015-03-30T04:00:24.910-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:43353 - MS Bulletins - May 2015" date="2015-05-28T14:09:00.599-04:00">
              <contributor organization="SecPod Technologies">Kumarswamy S</contributor>
            </modified>
            <status_change date="2015-05-28T14:13:09.638-04:00">INTERIM</status_change>
            <status_change date="2015-06-15T04:00:23.640-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Windows Server 2k3 and vulnerable file version">
          <criteria operator="OR" comment="Either OS">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criteria operator="OR" comment="either version">
            <criterion comment="Check if the version of win32k.sys is less than 5.2.3790.5513" test_ref="oval:org.mitre.oval:tst:137893"/>
            <criterion comment="Check if the version of Schannnel.dll is less than 5.2.3790.5516" test_ref="oval:org.mitre.oval:tst:137932"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Vista / 2k8 + vulnerable file version">
          <criteria operator="OR" comment="Vista / 2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.0.6002.19279" test_ref="oval:org.mitre.oval:tst:137920"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:81723"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.0.6002.23588" test_ref="oval:org.mitre.oval:tst:138008"/>
            </criteria>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of Ksecdd.sys is less than 6.0.6002.23592" test_ref="oval:org.mitre.oval:tst:137948"/>
              <criterion comment="Check if the version of Ksecdd.sys is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:137239"/>
            </criteria>
            <criterion comment="Check if the version of Ksecdd.sys is less than 6.0.6002.19282" test_ref="oval:org.mitre.oval:tst:138056"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / R2 + vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.18713" test_ref="oval:org.mitre.oval:tst:137986"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:81763"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.22919" test_ref="oval:org.mitre.oval:tst:137933"/>
            </criteria>
            <criterion comment="Check if the version of the Cng.sys is less than 6.1.7601.18717" test_ref="oval:org.mitre.oval:tst:138087"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of the Cng.sys is less than 6.1.7601.22923" test_ref="oval:org.mitre.oval:tst:138072"/>
              <criterion comment="Check if the version of the Cng.sys is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:137664"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8/2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.17226" test_ref="oval:org.mitre.oval:tst:138100"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:115678"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.21343" test_ref="oval:org.mitre.oval:tst:137841"/>
            </criteria>
            <criterion comment="Check if the version of the Cng.sys is less than 6.2.9200.17230" test_ref="oval:org.mitre.oval:tst:137968"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of the Cng.sys is less than 6.2.9200.21347" test_ref="oval:org.mitre.oval:tst:137865"/>
              <criterion comment="Check if the version of the Cng.sys is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:137956"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1 / 2K12 R2and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of win32k.sys is less than 6.3.9600.17630" test_ref="oval:org.mitre.oval:tst:137568"/>
          <criterion comment="Check if the version of the Cng.sys is less than 6.3.9600.17633" test_ref="oval:org.mitre.oval:tst:137745"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28688" version="5" class="vulnerability">
      <metadata>
        <title>Windows font driver denial of service vulnerability - CVE-2015-0060 (MS15-010)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-0060" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0060"/>
        <description>The font mapper in win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 does not properly scale fonts, which allows local users to cause a denial of service (system hang) via a crafted application, aka "Windows Font Driver Denial of Service Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-02-13T09:23:57">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-02-16T13:13:51.771-05:00">DRAFT</status_change>
            <status_change date="2015-03-09T04:01:48.917-04:00">INTERIM</status_change>
            <status_change date="2015-03-30T04:00:24.523-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:43353 - MS Bulletins - May 2015" date="2015-05-28T14:09:00.599-04:00">
              <contributor organization="SecPod Technologies">Kumarswamy S</contributor>
            </modified>
            <status_change date="2015-05-28T14:13:09.858-04:00">INTERIM</status_change>
            <status_change date="2015-06-15T04:00:23.222-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Windows Server 2k3 and vulnerable file version">
          <criteria operator="OR" comment="Either OS">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criteria operator="OR" comment="either version">
            <criterion comment="Check if the version of win32k.sys is less than 5.2.3790.5513" test_ref="oval:org.mitre.oval:tst:137893"/>
            <criterion comment="Check if the version of Schannnel.dll is less than 5.2.3790.5516" test_ref="oval:org.mitre.oval:tst:137932"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Vista / 2k8 + vulnerable file version">
          <criteria operator="OR" comment="Vista / 2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.0.6002.19279" test_ref="oval:org.mitre.oval:tst:137920"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:81723"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.0.6002.23588" test_ref="oval:org.mitre.oval:tst:138008"/>
            </criteria>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of Ksecdd.sys is less than 6.0.6002.23592" test_ref="oval:org.mitre.oval:tst:137948"/>
              <criterion comment="Check if the version of Ksecdd.sys is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:137239"/>
            </criteria>
            <criterion comment="Check if the version of Ksecdd.sys is less than 6.0.6002.19282" test_ref="oval:org.mitre.oval:tst:138056"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / R2 + vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.18713" test_ref="oval:org.mitre.oval:tst:137986"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:81763"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.22919" test_ref="oval:org.mitre.oval:tst:137933"/>
            </criteria>
            <criterion comment="Check if the version of the Cng.sys is less than 6.1.7601.18717" test_ref="oval:org.mitre.oval:tst:138087"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of the Cng.sys is less than 6.1.7601.22923" test_ref="oval:org.mitre.oval:tst:138072"/>
              <criterion comment="Check if the version of the Cng.sys is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:137664"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8/2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.17226" test_ref="oval:org.mitre.oval:tst:138100"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:115678"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.21343" test_ref="oval:org.mitre.oval:tst:137841"/>
            </criteria>
            <criterion comment="Check if the version of the Cng.sys is less than 6.2.9200.17230" test_ref="oval:org.mitre.oval:tst:137968"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of the Cng.sys is less than 6.2.9200.21347" test_ref="oval:org.mitre.oval:tst:137865"/>
              <criterion comment="Check if the version of the Cng.sys is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:137956"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1 / 2K12 R2and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of win32k.sys is less than 6.3.9600.17630" test_ref="oval:org.mitre.oval:tst:137568"/>
          <criterion comment="Check if the version of the Cng.sys is less than 6.3.9600.17633" test_ref="oval:org.mitre.oval:tst:137745"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28684" version="3" class="vulnerability">
      <metadata>
        <title>Adobe font driver remote code execution vulnerability - CVE-2015-0091 (MS15-021)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-0091" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0091"/>
        <description>Adobe Font Driver in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to execute arbitrary code via a crafted (1) web site or (2) file, aka "Adobe Font Driver Remote Code Execution Vulnerability," a different vulnerability than CVE-2015-0088, CVE-2015-0090, CVE-2015-0092, and CVE-2015-0093.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-03-16T10:01:42">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-03-17T10:44:51.497-04:00">DRAFT</status_change>
            <status_change date="2015-04-06T04:00:12.060-04:00">INTERIM</status_change>
            <status_change date="2015-04-27T04:00:20.728-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Server 2k3 and vulnerable file version">
          <criteria operator="OR" comment="2k3 (x86/x64/ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of atmfd.dll is less than 5.2.2.241" test_ref="oval:org.mitre.oval:tst:138235"/>
        </criteria>
        <criteria operator="AND" comment="Vista/2k8/Win7/2k8 R2/ Win 8/2k12/Win 8.1/2k12 R2 and vulnerable file version">
          <criteria operator="OR" comment="Vista/2k8/Win7/2k8 R2/ Win 8/2k12/Win 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of atmfd.dll is less than 5.1.2.241" test_ref="oval:org.mitre.oval:tst:137787"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28683" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-0052 (MS15-009)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-0052" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0052" source="CVE"/>
        <description>Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-0027, CVE-2015-0035, CVE-2015-0039, and CVE-2015-0068.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-02-13T10:59:59">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-02-16T13:11:29.508-05:00">DRAFT</status_change>
            <status_change date="2015-03-09T04:01:48.699-04:00">INTERIM</status_change>
            <status_change date="2015-03-30T04:00:24.205-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <criteria operator="AND" comment="Win 7/R2">
              <criteria operator="OR" comment="Win 7/R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17229" test_ref="oval:org.mitre.oval:tst:137987"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21345" test_ref="oval:org.mitre.oval:tst:137107"/>
                </criteria>
                <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.17241" test_ref="oval:org.mitre.oval:tst:137700"/>
                <criteria operator="AND" comment="Jscript.dll and LDR">
                  <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.21359" test_ref="oval:org.mitre.oval:tst:137021"/>
                  <criterion comment="Check if the version of Jscript9.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:137516"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 8/ 2012 R2">
              <criteria operator="OR" comment="Win 8/ 2012">
                <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
                <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
                <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17228" test_ref="oval:org.mitre.oval:tst:137876"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21345" test_ref="oval:org.mitre.oval:tst:137107"/>
                </criteria>
                <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.17241" test_ref="oval:org.mitre.oval:tst:137700"/>
                <criteria operator="AND" comment="Jscript.dll and LDR">
                  <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.21359" test_ref="oval:org.mitre.oval:tst:137021"/>
                  <criterion comment="Check if the version of Jscript9.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:137516"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/ 2k12 R2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7/ 2k8 R2/ 8.1/ 2k12 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criteria operator="OR" comment="either file">
                <criterion comment="Check if the version of Jscript9.dll is less than 11.0.9600.17640" test_ref="oval:org.mitre.oval:tst:137882"/>
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17631" test_ref="oval:org.mitre.oval:tst:137835"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28680" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-1714 (MS15-043)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-1714" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1714" source="CVE"/>
        <description>Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-05-20T08:43:05">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-05-28T14:16:18.628-04:00">DRAFT</status_change>
            <status_change date="2015-06-15T04:00:22.964-04:00">INTERIM</status_change>
            <status_change date="2015-07-06T04:00:21.686-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17357" test_ref="oval:org.mitre.oval:tst:138213"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21470" test_ref="oval:org.mitre.oval:tst:138585"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17801" test_ref="oval:org.mitre.oval:tst:138184"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28675" version="3" class="vulnerability">
      <metadata>
        <title>JPEG XR parser information disclosure vulnerability - CVE-2015-0076 (MS15-029)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-0076" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0076"/>
        <description>The photo-decoder implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 does not properly initialize memory for rendering of JXR images, which allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "JPEG XR Parser Information Disclosure Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-03-16T09:23:57">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-03-17T11:32:06.528-04:00">DRAFT</status_change>
            <status_change date="2015-04-06T04:00:11.733-04:00">INTERIM</status_change>
            <status_change date="2015-04-27T04:00:20.242-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vista / 2k8 + vulnerable file version">
          <criteria operator="OR" comment="Vista / 2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of Wmphoto.dll is less than 7.0.6002.19299" test_ref="oval:org.mitre.oval:tst:137741"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Wmphoto.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:138411"/>
              <criterion comment="Check if the version of Wmphoto.dll is less than 7.0.6002.23609" test_ref="oval:org.mitre.oval:tst:138249"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / R2 + vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of Wmphoto.dll is less than 6.1.7601.18742" test_ref="oval:org.mitre.oval:tst:138361"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Wmphoto.dll is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:138077"/>
              <criterion comment="Check if the version of Wmphoto.dll is less than 6.1.7601.22949" test_ref="oval:org.mitre.oval:tst:137949"/>
            </criteria>
            <criteria operator="AND" comment="Wmphoto.dll with version range 6.2.9200.xxxx">
              <criteria operator="OR" comment="gdr/ldr">
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of Wmphoto.dll is less than 6.2.9200.21371" test_ref="oval:org.mitre.oval:tst:137649"/>
                  <criterion comment="Check if the version of Wmphoto.dll is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:138341"/>
                </criteria>
                <criterion comment="Check if the version of Wmphoto.dll is less than 6.2.9200.17254" test_ref="oval:org.mitre.oval:tst:137935"/>
              </criteria>
              <criterion comment="Check if the version of Wmphoto.dll is greater than or equal to 6.2.9200.00000" test_ref="oval:org.mitre.oval:tst:138413"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win Server 2008 R2 IA64 + vulnerable file version">
          <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of Wmphoto.dll is less than 6.1.7601.18742" test_ref="oval:org.mitre.oval:tst:138361"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Wmphoto.dll is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:138077"/>
              <criterion comment="Check if the version of Wmphoto.dll is less than 6.1.7601.22949" test_ref="oval:org.mitre.oval:tst:137949"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8/2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of Wmphoto.dll is less than 6.2.9200.17247" test_ref="oval:org.mitre.oval:tst:138074"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Wmphoto.dll is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:137881"/>
              <criterion comment="Check if the version of Wmphoto.dll is less than 6.2.9200.21364" test_ref="oval:org.mitre.oval:tst:138010"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1 / 2K12 R2and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of Wmphoto.dll is less than 6.3.9600.17668" test_ref="oval:org.mitre.oval:tst:138258"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28672" version="3" class="vulnerability">
      <metadata>
        <title>Schannel information disclosure vulnerability - CVE-2015-1716 (MS15-055)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-1716" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1716"/>
        <description>Schannel in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 does not properly restrict Diffie-Hellman Ephemeral (DHE) key lengths, which makes it easier for remote attackers to defeat cryptographic protection mechanisms via unspecified vectors, aka "Schannel Information Disclosure Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-05-20T11:55:31">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-05-28T14:54:28.486-04:00">DRAFT</status_change>
            <status_change date="2015-06-15T04:00:22.618-04:00">INTERIM</status_change>
            <status_change date="2015-07-06T04:00:21.034-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Server 2003 and vulnerable file version">
          <criteria operator="OR" comment="Server 2003 (x86/x64/ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
          </criteria>
          <criterion comment="Check if the version of schannel.dll is less than 5.2.3790.5618" test_ref="oval:org.mitre.oval:tst:138556"/>
        </criteria>
        <criteria operator="AND" comment="Vista/2k8 and vulnerable file version">
          <criteria operator="OR" comment="Vista/2k8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of schannel.dll is less than 6.0.6002.19375" test_ref="oval:org.mitre.oval:tst:138676"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Schannel.dll is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:134478"/>
              <criterion comment="Check if the version of schannel.dll is less than 6.0.6002.23683" test_ref="oval:org.mitre.oval:tst:138299"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / R2 and vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of schannel.dll is less than 6.1.7601.18843" test_ref="oval:org.mitre.oval:tst:138711"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of schannel.dll is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:135418"/>
              <criterion comment="Check if the version of schannel.dll is less than 6.1.7601.23045" test_ref="oval:org.mitre.oval:tst:138601"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8 / 2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of schannel.dll is less than 6.2.9200.17361" test_ref="oval:org.mitre.oval:tst:138783"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Schannel.dll is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:135406"/>
              <criterion comment="Check if the version of schannel.dll is less than 6.2.9200.21473" test_ref="oval:org.mitre.oval:tst:138718"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1 / 2k12 R2 and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of schannel.dll is less than 6.3.9600.17810" test_ref="oval:org.mitre.oval:tst:138388"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28667" version="3" class="vulnerability">
      <metadata>
        <title>Microsoft windows kernel memory disclosure vulnerability - CVE-2015-0095 (MS15-023)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-0095" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0095"/>
        <description>The kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allow local users to cause a denial of service (NULL pointer dereference and blue screen), or obtain sensitive information from kernel memory and possibly bypass the ASLR protection mechanism, via a crafted application, aka "Microsoft Windows Kernel Memory Disclosure Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-03-16T09:23:57">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-03-17T10:55:40.719-04:00">DRAFT</status_change>
            <status_change date="2015-04-06T04:00:11.294-04:00">INTERIM</status_change>
            <status_change date="2015-04-27T04:00:19.698-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Windows Server 2k3 and vulnerable file version">
          <criteria operator="OR" comment="Either OS">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of win32k.sys is less than 5.2.3790.5561" test_ref="oval:org.mitre.oval:tst:138314"/>
        </criteria>
        <criteria operator="AND" comment="Vista / 2k8 + vulnerable file version">
          <criteria operator="OR" comment="Vista / 2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.0.6002.19327" test_ref="oval:org.mitre.oval:tst:138135"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:81723"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.0.6002.23636" test_ref="oval:org.mitre.oval:tst:138121"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / R2 + vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.18773" test_ref="oval:org.mitre.oval:tst:138032"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:81763"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.22978" test_ref="oval:org.mitre.oval:tst:138003"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8/2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.17287" test_ref="oval:org.mitre.oval:tst:138063"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:115678"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.21403" test_ref="oval:org.mitre.oval:tst:138335"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1 / 2K12 R2and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of win32k.sys is less than 6.3.9600.17694" test_ref="oval:org.mitre.oval:tst:138216"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28666" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability  - CVE-2015-0019 (MS15-009)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
        </affected>
        <reference ref_id="CVE-2015-0019" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0019" source="CVE"/>
        <description>Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-02-13T10:59:59">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-02-16T13:11:38.283-05:00">DRAFT</status_change>
            <status_change date="2015-03-09T04:01:48.274-04:00">INTERIM</status_change>
            <status_change date="2015-03-30T04:00:23.779-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16609" test_ref="oval:org.mitre.oval:tst:138073"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20725" test_ref="oval:org.mitre.oval:tst:137846"/>
            </criteria>
            <criterion comment="Check if the version of Jscript9.dll is less than 9.0.8112.16620" test_ref="oval:org.mitre.oval:tst:137873"/>
            <criteria operator="AND" comment="Jscript and LDR">
              <criterion comment="Check if the version of Jscript9.dll is less than 9.0.8112.20730" test_ref="oval:org.mitre.oval:tst:137974"/>
              <criterion comment="Check if the version of Jscript9.dll is greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:137868"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <criteria operator="AND" comment="Win 7/R2">
              <criteria operator="OR" comment="Win 7/R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17229" test_ref="oval:org.mitre.oval:tst:137987"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21345" test_ref="oval:org.mitre.oval:tst:137107"/>
                </criteria>
                <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.17241" test_ref="oval:org.mitre.oval:tst:137700"/>
                <criteria operator="AND" comment="Jscript.dll and LDR">
                  <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.21359" test_ref="oval:org.mitre.oval:tst:137021"/>
                  <criterion comment="Check if the version of Jscript9.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:137516"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 8/ 2012 R2">
              <criteria operator="OR" comment="Win 8/ 2012">
                <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
                <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
                <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17228" test_ref="oval:org.mitre.oval:tst:137876"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21345" test_ref="oval:org.mitre.oval:tst:137107"/>
                </criteria>
                <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.17241" test_ref="oval:org.mitre.oval:tst:137700"/>
                <criteria operator="AND" comment="Jscript.dll and LDR">
                  <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.21359" test_ref="oval:org.mitre.oval:tst:137021"/>
                  <criterion comment="Check if the version of Jscript9.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:137516"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28665" version="3" class="vulnerability">
      <metadata>
        <title>Win32k buffer overflow vulnerability - CVE-2015-1725 (MS15-061)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-1725" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1725"/>
        <description>Buffer overflow in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges via a crafted application, aka "Win32k Buffer Overflow Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-16T10:41:46">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-06-18T10:24:23.931-04:00">DRAFT</status_change>
            <status_change date="2015-07-06T04:00:20.626-04:00">INTERIM</status_change>
            <status_change date="2015-07-27T04:00:25.890-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Windows Server 2k3 and vulnerable file version">
          <criteria operator="OR" comment="Either OS">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of win32k.sys is less than 5.2.3790.5640" test_ref="oval:org.mitre.oval:tst:138918"/>
        </criteria>
        <criteria operator="AND" comment="Vista / 2k8 + vulnerable file version">
          <criteria operator="OR" comment="Vista / 2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.0.6002.19399" test_ref="oval:org.mitre.oval:tst:138917"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:81723"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.0.6002.23706" test_ref="oval:org.mitre.oval:tst:139029"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / R2 + vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.18869" test_ref="oval:org.mitre.oval:tst:138921"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:81763"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.23072" test_ref="oval:org.mitre.oval:tst:138932"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8/2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.17385" test_ref="oval:org.mitre.oval:tst:138372"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:115678"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.21496" test_ref="oval:org.mitre.oval:tst:138968"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1 / 2K12 R2and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of win32k.sys is less than 6.3.9600.17837" test_ref="oval:org.mitre.oval:tst:139008"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28664" version="3" class="vulnerability">
      <metadata>
        <title>Graphics component information disclosure vulnerability - CVE-2015-0002 (MS15-001)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-0002" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0002"/>
        <description>The AhcVerifyAdminContext function in ahcache.sys in the Application Compatibility component in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 does not verify that an impersonation token is associated with an administrative account, which allows local users to gain privileges by running AppCompatCache.exe with a crafted DLL file, aka MSRC ID 20544 or "Microsoft Application Compatibility Infrastructure Elevation of Privilege Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-01-16T11:10:08">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-01-16T19:04:43.938-05:00">DRAFT</status_change>
            <status_change date="2015-02-02T04:00:36.479-05:00">INTERIM</status_change>
            <status_change date="2015-02-23T04:01:32.500-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Win 7 / R2 + vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of Ntoskrnl.exe is less than 6.1.7601.18700" test_ref="oval:org.mitre.oval:tst:136995"/>
            <criteria operator="AND" comment="Check for LDR range">
              <criterion comment="Check if the version of Ntoskrnl.exe is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:81000"/>
              <criterion comment="Check if the version of Ntoskrnl.exe is less than 6.1.7601.22908" test_ref="oval:org.mitre.oval:tst:137258"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8/2k12 and vulnerable file version">
          <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of Ntoskrnl.exe is less than 6.2.9200.17214" test_ref="oval:org.mitre.oval:tst:137534"/>
            <criteria operator="AND" comment="Check for LDR range">
              <criterion comment="Check if the version of Ntoskrnl.exe is less than 6.2.9200.21317" test_ref="oval:org.mitre.oval:tst:137475"/>
              <criterion comment="Check if the version of Ntoskrnl.exe is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:137068"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8/2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of Ntoskrnl.exe is less than 6.2.9200.17213" test_ref="oval:org.mitre.oval:tst:137528"/>
            <criteria operator="AND" comment="Check for LDR range">
              <criterion comment="Check if the version of Ntoskrnl.exe is less than 6.2.9200.21317" test_ref="oval:org.mitre.oval:tst:137475"/>
              <criterion comment="Check if the version of Ntoskrnl.exe is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:137068"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1 / 2K12 R2and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of Ahcache.sys is less than 6.3.9600.17555" test_ref="oval:org.mitre.oval:tst:137524"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28658" version="5" class="vulnerability">
      <metadata>
        <title>Microsoft SharePoint xss vulnerability – CVE-2015-1636 (MS15-022)</title>
        <affected family="windows">
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <product>Microsoft SharePoint Foundation 2013</product>
          <product>Microsoft SharePoint Server 2013</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-1636" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1636"/>
        <description>Cross-site scripting (XSS) vulnerability in Microsoft SharePoint Foundation 2013 Gold and SP1 and SharePoint Server 2013 Gold and SP1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted request, aka "Microsoft SharePoint XSS Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-03-17T17:47:04">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-03-18T09:59:52.885-04:00">DRAFT</status_change>
            <status_change date="2015-04-06T04:00:11.162-04:00">INTERIM</status_change>
            <status_change date="2015-04-27T04:00:19.313-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:1569 - MS Bulletins - May 2015" date="2015-05-28T14:06:00.511-04:00">
              <contributor organization="SecPod Technologies">Kumarswamy S</contributor>
            </modified>
            <status_change date="2015-05-28T14:09:56.611-04:00">INTERIM</status_change>
            <status_change date="2015-06-15T04:00:22.408-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Sharepoint Foundation Server 2013 and vulnerable file version">
          <extend_definition comment="Microsoft SharePoint Foundation 2013 is installed" definition_ref="oval:org.mitre.oval:def:19090"/>
          <criterion comment="Check if the version of stswel.dll is less than 15.0.4701.1000" test_ref="oval:org.mitre.oval:tst:138170"/>
        </criteria>
        <criteria operator="AND" comment="Sharepoint Server 2013 and vulnerable file version">
          <extend_definition comment="Microsoft SharePoint Server 2013 is installed" definition_ref="oval:org.mitre.oval:def:16325"/>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of xlsrv.dll is less than 15.0.4701.1000" test_ref="oval:org.mitre.oval:tst:138254"/>
            <criterion comment="Check if the version of wwintl.dll is less than 15.0.4631.1000" test_ref="oval:org.mitre.oval:tst:138441"/>
            <criterion comment="Check if the version of vutils.dll is less than 15.0.4701.1000" test_ref="oval:org.mitre.oval:tst:138393"/>
            <criterion comment="Check if the version of microsoft.office.infopath.server.dll is less than 15.0.4701.1000" test_ref="oval:org.mitre.oval:tst:138339"/>
            <criterion comment="Check if the version of ascalc.dll is less than 15.0.4699.1000" test_ref="oval:org.mitre.oval:tst:138351"/>
            <criterion comment="Check if the version of msoserverintl.dll is less than 15.0.4697.1000" test_ref="oval:org.mitre.oval:tst:138449"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28656" version="3" class="vulnerability">
      <metadata>
        <title>Microsoft windows kernel memory disclosure vulnerability - CVE-2015-0094 (MS15-023)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-0094" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0094"/>
        <description>The kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 do not properly restrict the availability of address information during a function call, which makes it easier for local users to bypass the ASLR protection mechanism via a crafted application, aka "Microsoft Windows Kernel Memory Disclosure Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-03-16T09:23:57">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-03-17T10:55:35.174-04:00">DRAFT</status_change>
            <status_change date="2015-04-06T04:00:10.869-04:00">INTERIM</status_change>
            <status_change date="2015-04-27T04:00:18.878-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Windows Server 2k3 and vulnerable file version">
          <criteria operator="OR" comment="Either OS">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of win32k.sys is less than 5.2.3790.5561" test_ref="oval:org.mitre.oval:tst:138314"/>
        </criteria>
        <criteria operator="AND" comment="Vista / 2k8 + vulnerable file version">
          <criteria operator="OR" comment="Vista / 2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.0.6002.19327" test_ref="oval:org.mitre.oval:tst:138135"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:81723"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.0.6002.23636" test_ref="oval:org.mitre.oval:tst:138121"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / R2 + vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.18773" test_ref="oval:org.mitre.oval:tst:138032"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:81763"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.22978" test_ref="oval:org.mitre.oval:tst:138003"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8/2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.17287" test_ref="oval:org.mitre.oval:tst:138063"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:115678"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.21403" test_ref="oval:org.mitre.oval:tst:138335"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1 / 2K12 R2and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of win32k.sys is less than 6.3.9600.17694" test_ref="oval:org.mitre.oval:tst:138216"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28653" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-0031 (MS15-009)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
          <product>Microsoft Internet Explorer 6</product>
        </affected>
        <reference ref_id="CVE-2015-0031" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0031" source="CVE"/>
        <description>Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-0017, CVE-2015-0020, CVE-2015-0022, CVE-2015-0026, CVE-2015-0030, CVE-2015-0036, and CVE-2015-0041.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-02-13T10:59:59">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-02-16T13:11:05.422-05:00">DRAFT</status_change>
            <status_change date="2015-03-09T04:01:47.712-04:00">INTERIM</status_change>
            <status_change date="2015-03-30T04:00:23.031-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5508" test_ref="oval:org.mitre.oval:tst:137925"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21432" test_ref="oval:org.mitre.oval:tst:138027"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista / 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19281" test_ref="oval:org.mitre.oval:tst:138002"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23590" test_ref="oval:org.mitre.oval:tst:137924"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23644" test_ref="oval:org.mitre.oval:tst:137686"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19600" test_ref="oval:org.mitre.oval:tst:137706"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23655" test_ref="oval:org.mitre.oval:tst:137677"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18715" test_ref="oval:org.mitre.oval:tst:138039"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22921" test_ref="oval:org.mitre.oval:tst:137991"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16609" test_ref="oval:org.mitre.oval:tst:138073"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20725" test_ref="oval:org.mitre.oval:tst:137846"/>
            </criteria>
            <criterion comment="Check if the version of Jscript9.dll is less than 9.0.8112.16620" test_ref="oval:org.mitre.oval:tst:137873"/>
            <criteria operator="AND" comment="Jscript and LDR">
              <criterion comment="Check if the version of Jscript9.dll is less than 9.0.8112.20730" test_ref="oval:org.mitre.oval:tst:137974"/>
              <criterion comment="Check if the version of Jscript9.dll is greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:137868"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <criteria operator="AND" comment="Win 7/R2">
              <criteria operator="OR" comment="Win 7/R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17229" test_ref="oval:org.mitre.oval:tst:137987"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21345" test_ref="oval:org.mitre.oval:tst:137107"/>
                </criteria>
                <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.17241" test_ref="oval:org.mitre.oval:tst:137700"/>
                <criteria operator="AND" comment="Jscript.dll and LDR">
                  <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.21359" test_ref="oval:org.mitre.oval:tst:137021"/>
                  <criterion comment="Check if the version of Jscript9.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:137516"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 8/ 2012 R2">
              <criteria operator="OR" comment="Win 8/ 2012">
                <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
                <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
                <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17228" test_ref="oval:org.mitre.oval:tst:137876"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21345" test_ref="oval:org.mitre.oval:tst:137107"/>
                </criteria>
                <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.17241" test_ref="oval:org.mitre.oval:tst:137700"/>
                <criteria operator="AND" comment="Jscript.dll and LDR">
                  <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.21359" test_ref="oval:org.mitre.oval:tst:137021"/>
                  <criterion comment="Check if the version of Jscript9.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:137516"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/ 2k12 R2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7/ 2k8 R2/ 8.1/ 2k12 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criteria operator="OR" comment="either file">
                <criterion comment="Check if the version of Jscript9.dll is less than 11.0.9600.17640" test_ref="oval:org.mitre.oval:tst:137882"/>
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17631" test_ref="oval:org.mitre.oval:tst:137835"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28650" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-1741 (MS15-056)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-1741" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1741" source="CVE"/>
        <description>Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-1752.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-16T04:41:39">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-06-18T10:14:10.880-04:00">DRAFT</status_change>
            <status_change date="2015-07-06T04:00:20.163-04:00">INTERIM</status_change>
            <status_change date="2015-07-27T04:00:25.223-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16659" test_ref="oval:org.mitre.oval:tst:138475"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20774" test_ref="oval:org.mitre.oval:tst:138843"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17377" test_ref="oval:org.mitre.oval:tst:139004"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21489" test_ref="oval:org.mitre.oval:tst:138844"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17842" test_ref="oval:org.mitre.oval:tst:138937"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28649" version="3" class="vulnerability">
      <metadata>
        <title>Windows Journal remote code execution vulnerability - CVE-2015-1698 (MS15-045)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-1698" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1698"/>
        <description>Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allow remote attackers to execute arbitrary code via a crafted Journal file, aka "Windows Journal Remote Code Execution Vulnerability," a different vulnerability than CVE-2015-1675, CVE-2015-1695, CVE-2015-1696, CVE-2015-1697, and CVE-2015-1699.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-05-20T18:56:32">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-05-28T14:32:55.364-04:00">DRAFT</status_change>
            <status_change date="2015-06-15T04:00:21.993-04:00">INTERIM</status_change>
            <status_change date="2015-07-06T04:00:19.783-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vista / 2k8 + vulnerable file version">
          <criteria operator="OR" comment="Vista / 2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Journal.dll is less than 6.0.6002.23664" test_ref="oval:org.mitre.oval:tst:138166"/>
              <criterion comment="Check if the version of Journal.dll is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:138660"/>
            </criteria>
            <criterion comment="Check if the version of Journal.dll is less than 6.0.6002.19356" test_ref="oval:org.mitre.oval:tst:138728"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / R2 + vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Journal.dll is less than 6.1.7601.23020" test_ref="oval:org.mitre.oval:tst:138830"/>
              <criterion comment="Check if the version of Journal.dll is greater than or equal to 6.1.7601.23000" test_ref="oval:org.mitre.oval:tst:138508"/>
            </criteria>
            <criterion comment="Check if the version of Journal.dll is less than 6.1.7601.18815" test_ref="oval:org.mitre.oval:tst:138819"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8/2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Journal.dll is less than 6.2.9200.21444" test_ref="oval:org.mitre.oval:tst:138174"/>
              <criterion comment="Check if the version of Journal.dll is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:138277"/>
            </criteria>
            <criterion comment="Check if the version of Journal.dll is less than 6.2.9200.17330" test_ref="oval:org.mitre.oval:tst:138698"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1 / 2K12 R2and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of Journal.dll is less than 6.3.9600.17793" test_ref="oval:org.mitre.oval:tst:138477"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28641" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-1688 (MS15-043)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-1688" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1688" source="CVE"/>
        <description>Microsoft Internet Explorer 7 through 11 allows remote attackers to gain privileges via a crafted web site, aka "Internet Explorer Elevation of Privilege Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-05-20T08:43:05">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-05-28T14:16:14.393-04:00">DRAFT</status_change>
            <status_change date="2015-06-15T04:00:21.161-04:00">INTERIM</status_change>
            <status_change date="2015-07-06T04:00:18.368-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21455" test_ref="oval:org.mitre.oval:tst:138315"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista / 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19367" test_ref="oval:org.mitre.oval:tst:137942"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23675" test_ref="oval:org.mitre.oval:tst:138544"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23676" test_ref="oval:org.mitre.oval:tst:138485"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19621" test_ref="oval:org.mitre.oval:tst:138412"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23676" test_ref="oval:org.mitre.oval:tst:138485"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18835" test_ref="oval:org.mitre.oval:tst:138592"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.23038" test_ref="oval:org.mitre.oval:tst:137853"/>
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.23000" test_ref="oval:org.mitre.oval:tst:138202"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16644" test_ref="oval:org.mitre.oval:tst:138514"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20758" test_ref="oval:org.mitre.oval:tst:138561"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17357" test_ref="oval:org.mitre.oval:tst:138213"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21470" test_ref="oval:org.mitre.oval:tst:138585"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17801" test_ref="oval:org.mitre.oval:tst:138184"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28634" version="3" class="vulnerability">
      <metadata>
        <title>Windows Error Reporting security feature bypass vulnerability - CVE-2015-0001 (MS15-006)</title>
        <affected family="windows">
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-0001" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0001"/>
        <description>The Windows Error Reporting (WER) component in Microsoft Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to bypass the Protected Process Light protection mechanism and read the contents of arbitrary process-memory locations by leveraging administrative privileges, aka "Windows Error Reporting Security Feature Bypass Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-01-16T11:10:08">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-01-16T19:27:27.561-05:00">DRAFT</status_change>
            <status_change date="2015-02-02T04:00:34.848-05:00">INTERIM</status_change>
            <status_change date="2015-02-23T04:01:31.156-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Win 8 / 2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of wer.dll is less than 6.2.9200.17199" test_ref="oval:org.mitre.oval:tst:137389"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of wer.dll is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:137185"/>
              <criterion comment="Check if the version of wer.dll is less than 6.2.9200.21316" test_ref="oval:org.mitre.oval:tst:136740"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1 / 2k12 R2 and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of wer.dll is less than 6.3.9600.17550" test_ref="oval:org.mitre.oval:tst:137668"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28633" version="5" class="vulnerability">
      <metadata>
        <title>TrueType font parsing remote code execution vulnerability - CVE-2015-0059 (MS15-010)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-0059" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0059"/>
        <description>win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2008 R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges via a crafted TrueType font, aka "TrueType Font Parsing Remote Code Execution Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-02-13T09:23:57">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-02-16T13:13:49.822-05:00">DRAFT</status_change>
            <status_change date="2015-03-09T04:01:47.127-04:00">INTERIM</status_change>
            <status_change date="2015-03-30T04:00:22.245-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:43353 - MS Bulletins - May 2015" date="2015-05-28T14:09:00.599-04:00">
              <contributor organization="SecPod Technologies">Kumarswamy S</contributor>
            </modified>
            <status_change date="2015-05-28T14:13:10.104-04:00">INTERIM</status_change>
            <status_change date="2015-06-15T04:00:20.800-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Win 7 / R2 + vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.18713" test_ref="oval:org.mitre.oval:tst:137986"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:81763"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.22919" test_ref="oval:org.mitre.oval:tst:137933"/>
            </criteria>
            <criterion comment="Check if the version of the Cng.sys is less than 6.1.7601.18717" test_ref="oval:org.mitre.oval:tst:138087"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of the Cng.sys is less than 6.1.7601.22923" test_ref="oval:org.mitre.oval:tst:138072"/>
              <criterion comment="Check if the version of the Cng.sys is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:137664"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8/2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.17226" test_ref="oval:org.mitre.oval:tst:138100"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:115678"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.21343" test_ref="oval:org.mitre.oval:tst:137841"/>
            </criteria>
            <criterion comment="Check if the version of the Cng.sys is less than 6.2.9200.17230" test_ref="oval:org.mitre.oval:tst:137968"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of the Cng.sys is less than 6.2.9200.21347" test_ref="oval:org.mitre.oval:tst:137865"/>
              <criterion comment="Check if the version of the Cng.sys is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:137956"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1 / 2K12 R2and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of win32k.sys is less than 6.3.9600.17630" test_ref="oval:org.mitre.oval:tst:137568"/>
          <criterion comment="Check if the version of the Cng.sys is less than 6.3.9600.17633" test_ref="oval:org.mitre.oval:tst:137745"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28624" version="4" class="vulnerability" deprecated="true">
      <metadata>
        <title>DEPRECATED: DLL planting remote code execution vulnerability - CVE-2015-0096 (MS15-020)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-0096" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0096"/>
        <description>Untrusted search path vulnerability in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges via a Trojan horse DLL in the current working directory, leading to DLL loading during Windows Explorer access to the icon of a crafted shortcut, aka "DLL Planting Remote Code Execution Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-03-16T12:40:27">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-03-17T10:40:17.798-04:00">DRAFT</status_change>
            <status_change date="2015-04-06T04:00:10.178-04:00">INTERIM</status_change>
            <status_change date="2015-04-27T04:00:17.952-04:00">ACCEPTED</status_change>
            <modified comment="Duplicate of def:28609" date="2015-05-06T14:06:09.994-04:00">
              <contributor organization="baramundi software">Richard Helbing</contributor>
            </modified>
            <status_change date="2015-05-06T14:06:09.994-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Windows 2003 and vulnerable file versions">
          <criteria operator="OR" comment="Win 2k3 (x86/x64/ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of shell32.dll is less than 6.0.3790.5558" test_ref="oval:org.mitre.oval:tst:138302"/>
        </criteria>
        <criteria operator="AND" comment="Vista /2k8 and vulnerable file versions">
          <criteria operator="OR" comment="Vista / 2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of shell32.dll is less than 6.0.6002.19322" test_ref="oval:org.mitre.oval:tst:138377"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of shell32.dll is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:113981"/>
              <criterion comment="Check if the version of shell32.dll is less than 6.0.6002.23632" test_ref="oval:org.mitre.oval:tst:138023"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 /2k8 R2 and vulnerable file versions">
          <criteria operator="OR" comment="Win 7 / 2k8 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of shell32.dll is less than 6.1.7601.18762" test_ref="oval:org.mitre.oval:tst:138303"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of shell32.dll is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:113444"/>
              <criterion comment="Check if the version of shell32.dll is less than 6.1.7601.22969" test_ref="oval:org.mitre.oval:tst:138272"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8 /2k12 and vulnerable file versions">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of shell32.dll is less than 6.2.9200.17279" test_ref="oval:org.mitre.oval:tst:138140"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of shell32.dll is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:137937"/>
              <criterion comment="Check if the version of shell32.dll is less than 6.2.9200.21395" test_ref="oval:org.mitre.oval:tst:138060"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1 /2k12 R2 and vulnerable file versions">
          <criteria operator="OR" comment="Win 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of shell32.dll is less than 6.3.9600.17680" test_ref="oval:org.mitre.oval:tst:138190"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28623" version="3" class="vulnerability">
      <metadata>
        <title>HTTP.sys Remote code execution vulnerability - CVE-2015-1635 (MS15-034)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-1635" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1635"/>
        <description>HTTP.sys in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 allows remote attackers to execute arbitrary code via crafted HTTP requests, aka "HTTP.sys Remote Code Execution Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-04-17T14:55:27">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-04-23T10:14:50.653-04:00">DRAFT</status_change>
            <status_change date="2015-05-11T04:00:17.227-04:00">INTERIM</status_change>
            <status_change date="2015-06-01T04:00:18.860-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Win 7 / R2 + vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of http.sys is less than 6.1.7601.22976" test_ref="oval:org.mitre.oval:tst:138500"/>
              <criterion comment="Check if the version of http.sys is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:138391"/>
            </criteria>
            <criterion comment="Check if the version of http.sys is less than 6.1.7601.18772" test_ref="oval:org.mitre.oval:tst:138381"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8/2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of http.sys is less than 6.2.9200.21401" test_ref="oval:org.mitre.oval:tst:138499"/>
              <criterion comment="Check if the version of http.sys is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:137708"/>
            </criteria>
            <criterion comment="Check if the version of http.sys is less than 6.2.9200.17285" test_ref="oval:org.mitre.oval:tst:138346"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1 / 2K12 R2and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of http.sys is less than 6.3.9600.17712" test_ref="oval:org.mitre.oval:tst:138014"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28609" version="3" class="vulnerability">
      <metadata>
        <title>DLL planting remote code execution vulnerability - CVE-2015-0096 (MS15-020)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-0096" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0096"/>
        <description>Untrusted search path vulnerability in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges via a Trojan horse DLL in the current working directory, leading to DLL loading during Windows Explorer access to the icon of a crafted shortcut, aka "DLL Planting Remote Code Execution Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-03-16T12:40:27">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-03-17T10:49:20.296-04:00">DRAFT</status_change>
            <status_change date="2015-04-06T04:00:09.924-04:00">INTERIM</status_change>
            <status_change date="2015-04-27T04:00:17.588-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Windows 2003 and vulnerable file versions">
          <criteria operator="OR" comment="Win 2k3 (x86/x64/ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of shell32.dll is less than 6.0.3790.5558" test_ref="oval:org.mitre.oval:tst:137978"/>
        </criteria>
        <criteria operator="AND" comment="Vista /2k8 and vulnerable file versions">
          <criteria operator="OR" comment="Vista / 2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of shell32.dll is less than 6.0.6002.19322" test_ref="oval:org.mitre.oval:tst:137997"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of shell32.dll is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:113981"/>
              <criterion comment="Check if the version of shell32.dll is less than 6.0.6002.23632" test_ref="oval:org.mitre.oval:tst:138386"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 /2k8 R2 and vulnerable file versions">
          <criteria operator="OR" comment="Win 7 / 2k8 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of shell32.dll is less than 6.1.7601.18762" test_ref="oval:org.mitre.oval:tst:138107"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of shell32.dll is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:113444"/>
              <criterion comment="Check if the version of shell32.dll is less than 6.1.7601.22969" test_ref="oval:org.mitre.oval:tst:138138"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8 /2k12 and vulnerable file versions">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of shell32.dll is less than 6.2.9200.17279" test_ref="oval:org.mitre.oval:tst:138337"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of shell32.dll is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:138161"/>
              <criterion comment="Check if the version of shell32.dll is less than 6.2.9200.21395" test_ref="oval:org.mitre.oval:tst:138265"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1 /2k12 R2 and vulnerable file versions">
          <criteria operator="OR" comment="Win 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of shell32.dll is less than 6.3.9600.17680" test_ref="oval:org.mitre.oval:tst:138266"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28605" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer elevation of privilege vulnerability - CVE-2015-1627 (MS15-018)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-1627" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1627" source="CVE"/>
        <description>Microsoft Internet Explorer 7 through 11 allows remote attackers to gain privileges via a crafted web site, aka "Internet Explorer Elevation of Privilege Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-03-16T09:23:57">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-03-17T10:36:41.386-04:00">DRAFT</status_change>
            <status_change date="2015-04-06T04:00:09.609-04:00">INTERIM</status_change>
            <status_change date="2015-04-27T04:00:17.125-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21443" test_ref="oval:org.mitre.oval:tst:137862"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista / 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19310" test_ref="oval:org.mitre.oval:tst:138155"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23620" test_ref="oval:org.mitre.oval:tst:138114"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23661" test_ref="oval:org.mitre.oval:tst:138196"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19607" test_ref="oval:org.mitre.oval:tst:138058"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23661" test_ref="oval:org.mitre.oval:tst:138196"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18751" test_ref="oval:org.mitre.oval:tst:137478"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22958" test_ref="oval:org.mitre.oval:tst:138221"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16633" test_ref="oval:org.mitre.oval:tst:137971"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20747" test_ref="oval:org.mitre.oval:tst:137783"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17267" test_ref="oval:org.mitre.oval:tst:138160"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21384" test_ref="oval:org.mitre.oval:tst:138199"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17690" test_ref="oval:org.mitre.oval:tst:138148"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28603" version="3" class="vulnerability">
      <metadata>
        <title>Windows MS-DOS device name vulnerability - CVE-2015-1644 (MS15-038)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 8.1</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-1644" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1644"/>
        <description>Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 do not properly constrain impersonation levels, which allows local users to gain privileges via a crafted application, aka "Windows MS-DOS Device Name Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-04-17T09:23:31">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-04-23T10:20:32.765-04:00">DRAFT</status_change>
            <status_change date="2015-05-11T04:00:16.667-04:00">INTERIM</status_change>
            <status_change date="2015-06-01T04:00:18.546-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Server 2003(x86/x64) and vulnerable file versions">
          <criteria operator="OR" comment="Server 2003 (x86/x64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
          </criteria>
          <criterion comment="Check if the version of ntoskrnl.exe is less than 5.2.3790.5583" test_ref="oval:org.mitre.oval:tst:138376"/>
        </criteria>
        <criteria operator="AND" comment="Server 2003 IA64 and vulnerable file version">
          <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          <criterion comment="Check if the version of Ntkrnlmp.exe is less than 5.2.3790.5583" test_ref="oval:org.mitre.oval:tst:138097"/>
        </criteria>
        <criteria operator="AND" comment="Vista/2k8 and vulnerable file version">
          <criteria operator="OR" comment="Vista/2k8(x86/x64/ia64)">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of ntoskrnl.exe is less than 6.0.6002.19346" test_ref="oval:org.mitre.oval:tst:138013"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Ntoskrnl.exe is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80719"/>
              <criterion comment="Check if the version of ntoskrnl.exe is less than 6.0.6002.23654" test_ref="oval:org.mitre.oval:tst:138515"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / R2 and vulnerable file version">
          <criteria operator="OR" comment="Win 7/ R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of ntoskrnl.exe is less than 6.1.7601.18798" test_ref="oval:org.mitre.oval:tst:137967"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of ntoskrnl.exe is greater than or equal to 6.1.7601.23000" test_ref="oval:org.mitre.oval:tst:138152"/>
              <criterion comment="Check if the version of ntoskrnl.exe is less than 6.1.7601.23002" test_ref="oval:org.mitre.oval:tst:138528"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8 / 2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8/2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of ntoskrnl.exe is less than 6.2.9200.17313" test_ref="oval:org.mitre.oval:tst:138572"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Ntoskrnl.exe is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:137068"/>
              <criterion comment="Check if the version of ntoskrnl.exe is less than 6.2.9200.21428" test_ref="oval:org.mitre.oval:tst:138550"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1/Server 2012 R2 and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of ntoskrnl.exe is less than 6.3.9600.17736" test_ref="oval:org.mitre.oval:tst:138069"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28576" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-1694 (MS15-043)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-1694" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1694" source="CVE"/>
        <description>Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-1710.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-05-20T08:43:05">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-05-28T14:15:58.611-04:00">DRAFT</status_change>
            <status_change date="2015-06-15T04:00:19.406-04:00">INTERIM</status_change>
            <status_change date="2015-07-06T04:00:17.074-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5602" test_ref="oval:org.mitre.oval:tst:138124"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21455" test_ref="oval:org.mitre.oval:tst:138315"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista / 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19367" test_ref="oval:org.mitre.oval:tst:137942"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23675" test_ref="oval:org.mitre.oval:tst:138544"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23676" test_ref="oval:org.mitre.oval:tst:138485"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19621" test_ref="oval:org.mitre.oval:tst:138412"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23676" test_ref="oval:org.mitre.oval:tst:138485"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18835" test_ref="oval:org.mitre.oval:tst:138592"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.23038" test_ref="oval:org.mitre.oval:tst:137853"/>
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.23000" test_ref="oval:org.mitre.oval:tst:138202"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16644" test_ref="oval:org.mitre.oval:tst:138514"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20758" test_ref="oval:org.mitre.oval:tst:138561"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17357" test_ref="oval:org.mitre.oval:tst:138213"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21470" test_ref="oval:org.mitre.oval:tst:138585"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17801" test_ref="oval:org.mitre.oval:tst:138184"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28573" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-0043 (MS15-009)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-0043" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0043" source="CVE"/>
        <description>Microsoft Internet Explorer 8 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-02-13T10:59:59">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-02-16T13:11:00.683-05:00">DRAFT</status_change>
            <status_change date="2015-03-09T04:01:45.664-04:00">INTERIM</status_change>
            <status_change date="2015-03-30T04:00:20.527-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23644" test_ref="oval:org.mitre.oval:tst:137686"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19600" test_ref="oval:org.mitre.oval:tst:137706"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23655" test_ref="oval:org.mitre.oval:tst:137677"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18715" test_ref="oval:org.mitre.oval:tst:138039"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22921" test_ref="oval:org.mitre.oval:tst:137991"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16609" test_ref="oval:org.mitre.oval:tst:138073"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20725" test_ref="oval:org.mitre.oval:tst:137846"/>
            </criteria>
            <criterion comment="Check if the version of Jscript9.dll is less than 9.0.8112.16620" test_ref="oval:org.mitre.oval:tst:137873"/>
            <criteria operator="AND" comment="Jscript and LDR">
              <criterion comment="Check if the version of Jscript9.dll is less than 9.0.8112.20730" test_ref="oval:org.mitre.oval:tst:137974"/>
              <criterion comment="Check if the version of Jscript9.dll is greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:137868"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <criteria operator="AND" comment="Win 7/R2">
              <criteria operator="OR" comment="Win 7/R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17229" test_ref="oval:org.mitre.oval:tst:137987"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21345" test_ref="oval:org.mitre.oval:tst:137107"/>
                </criteria>
                <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.17241" test_ref="oval:org.mitre.oval:tst:137700"/>
                <criteria operator="AND" comment="Jscript.dll and LDR">
                  <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.21359" test_ref="oval:org.mitre.oval:tst:137021"/>
                  <criterion comment="Check if the version of Jscript9.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:137516"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 8/ 2012 R2">
              <criteria operator="OR" comment="Win 8/ 2012">
                <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
                <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
                <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17228" test_ref="oval:org.mitre.oval:tst:137876"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21345" test_ref="oval:org.mitre.oval:tst:137107"/>
                </criteria>
                <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.17241" test_ref="oval:org.mitre.oval:tst:137700"/>
                <criteria operator="AND" comment="Jscript.dll and LDR">
                  <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.21359" test_ref="oval:org.mitre.oval:tst:137021"/>
                  <criterion comment="Check if the version of Jscript9.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:137516"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/ 2k12 R2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7/ 2k8 R2/ 8.1/ 2k12 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criteria operator="OR" comment="either file">
                <criterion comment="Check if the version of Jscript9.dll is less than 11.0.9600.17640" test_ref="oval:org.mitre.oval:tst:137882"/>
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17631" test_ref="oval:org.mitre.oval:tst:137835"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28569" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-1634 (MS15-018)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-1634" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1634" source="CVE"/>
        <description>Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-1625.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-03-16T09:23:57">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-03-17T10:36:24.225-04:00">DRAFT</status_change>
            <status_change date="2015-04-06T04:00:09.295-04:00">INTERIM</status_change>
            <status_change date="2015-04-27T04:00:16.655-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5543" test_ref="oval:org.mitre.oval:tst:138082"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21443" test_ref="oval:org.mitre.oval:tst:137862"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista / 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19310" test_ref="oval:org.mitre.oval:tst:138155"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23620" test_ref="oval:org.mitre.oval:tst:138114"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23661" test_ref="oval:org.mitre.oval:tst:138196"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19607" test_ref="oval:org.mitre.oval:tst:138058"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23661" test_ref="oval:org.mitre.oval:tst:138196"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18751" test_ref="oval:org.mitre.oval:tst:137478"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22958" test_ref="oval:org.mitre.oval:tst:138221"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16633" test_ref="oval:org.mitre.oval:tst:137971"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20747" test_ref="oval:org.mitre.oval:tst:137783"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17267" test_ref="oval:org.mitre.oval:tst:138160"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21384" test_ref="oval:org.mitre.oval:tst:138199"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17690" test_ref="oval:org.mitre.oval:tst:138148"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28562" version="3" class="vulnerability">
      <metadata>
        <title>Vulnerability in Microsoft Schannel could allow security feature bypass - CVE-2015-1637 (MS15-031)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-1637" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1637"/>
        <description>Schannel (aka Secure Channel) in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 does not properly restrict TLS state transitions, which makes it easier for remote attackers to conduct cipher-downgrade attacks to EXPORT_RSA ciphers via crafted TLS traffic, related to the "FREAK" issue, a different vulnerability than CVE-2015-0204 and CVE-2015-1067.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-03-17T10:59:59">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-03-18T10:05:02.556-04:00">DRAFT</status_change>
            <status_change date="2015-04-06T04:00:08.997-04:00">INTERIM</status_change>
            <status_change date="2015-04-27T04:00:16.285-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Check for Windows Server 2003 x86/x64 and vulnerable file version">
          <criteria operator="OR" comment="Check for Windows Server 2003 x86/x64 or Windows XP x86">
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of Schannel.dll is less than 5.2.3790.5564" test_ref="oval:org.mitre.oval:tst:138366"/>
        </criteria>
        <criteria operator="AND" comment="Vista / 2k8 + vulnerable file version">
          <criteria operator="OR" comment="Vista / 2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="Check for LDR/GDR">
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Schannel.dll is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:134478"/>
              <criterion comment="Check if the version of Schannel.dll is less than 6.0.6002.23640" test_ref="oval:org.mitre.oval:tst:138169"/>
            </criteria>
            <criterion comment="Check if the version of Schannel.dll is less than 6.0.6002.19332" test_ref="oval:org.mitre.oval:tst:137934"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / R2 + vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="Check for LDR/GDR">
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of schannel.dll is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:135418"/>
              <criterion comment="Check if the version of Schannel.dll is less than 6.1.7601.22983" test_ref="oval:org.mitre.oval:tst:137769"/>
            </criteria>
            <criterion comment="Check if the version of Schannel.dll is less than 6.1.7601.18779" test_ref="oval:org.mitre.oval:tst:138168"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8/2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Schannel.dll is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:135406"/>
              <criterion comment="Check if the version of Schannel.dll is less than 6.2.9200.21410" test_ref="oval:org.mitre.oval:tst:138230"/>
            </criteria>
            <criterion comment="Check if the version of Schannel.dll is less than 6.2.9200.17293" test_ref="oval:org.mitre.oval:tst:138298"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1 / 2K12 R2and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of Schannel.dll is less than 6.3.9600.17702" test_ref="oval:org.mitre.oval:tst:138186"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28558" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-0026 (MS15-009)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
          <product>Microsoft Internet Explorer 6</product>
        </affected>
        <reference ref_id="CVE-2015-0026" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0026" source="CVE"/>
        <description>Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-0017, CVE-2015-0020, CVE-2015-0022, CVE-2015-0030, CVE-2015-0031, CVE-2015-0036, and CVE-2015-0041.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-02-13T10:59:59">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-02-16T13:10:58.146-05:00">DRAFT</status_change>
            <status_change date="2015-03-09T04:01:45.343-04:00">INTERIM</status_change>
            <status_change date="2015-03-30T04:00:20.117-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5508" test_ref="oval:org.mitre.oval:tst:137925"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21432" test_ref="oval:org.mitre.oval:tst:138027"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista / 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19281" test_ref="oval:org.mitre.oval:tst:138002"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23590" test_ref="oval:org.mitre.oval:tst:137924"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23644" test_ref="oval:org.mitre.oval:tst:137686"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19600" test_ref="oval:org.mitre.oval:tst:137706"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23655" test_ref="oval:org.mitre.oval:tst:137677"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18715" test_ref="oval:org.mitre.oval:tst:138039"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22921" test_ref="oval:org.mitre.oval:tst:137991"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16609" test_ref="oval:org.mitre.oval:tst:138073"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20725" test_ref="oval:org.mitre.oval:tst:137846"/>
            </criteria>
            <criterion comment="Check if the version of Jscript9.dll is less than 9.0.8112.16620" test_ref="oval:org.mitre.oval:tst:137873"/>
            <criteria operator="AND" comment="Jscript and LDR">
              <criterion comment="Check if the version of Jscript9.dll is less than 9.0.8112.20730" test_ref="oval:org.mitre.oval:tst:137974"/>
              <criterion comment="Check if the version of Jscript9.dll is greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:137868"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <criteria operator="AND" comment="Win 7/R2">
              <criteria operator="OR" comment="Win 7/R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17229" test_ref="oval:org.mitre.oval:tst:137987"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21345" test_ref="oval:org.mitre.oval:tst:137107"/>
                </criteria>
                <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.17241" test_ref="oval:org.mitre.oval:tst:137700"/>
                <criteria operator="AND" comment="Jscript.dll and LDR">
                  <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.21359" test_ref="oval:org.mitre.oval:tst:137021"/>
                  <criterion comment="Check if the version of Jscript9.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:137516"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 8/ 2012 R2">
              <criteria operator="OR" comment="Win 8/ 2012">
                <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
                <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
                <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17228" test_ref="oval:org.mitre.oval:tst:137876"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21345" test_ref="oval:org.mitre.oval:tst:137107"/>
                </criteria>
                <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.17241" test_ref="oval:org.mitre.oval:tst:137700"/>
                <criteria operator="AND" comment="Jscript.dll and LDR">
                  <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.21359" test_ref="oval:org.mitre.oval:tst:137021"/>
                  <criterion comment="Check if the version of Jscript9.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:137516"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/ 2k12 R2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7/ 2k8 R2/ 8.1/ 2k12 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criteria operator="OR" comment="either file">
                <criterion comment="Check if the version of Jscript9.dll is less than 11.0.9600.17640" test_ref="oval:org.mitre.oval:tst:137882"/>
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17631" test_ref="oval:org.mitre.oval:tst:137835"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28555" version="3" class="vulnerability">
      <metadata>
        <title>Microsoft windows kernel memory disclosure vulnerability - CVE-2015-1679 (MS15-051)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-1679" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1679"/>
        <description>The kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allow local users to bypass the ASLR protection mechanism via a crafted function call, aka "Microsoft Windows Kernel Memory Disclosure Vulnerability," a different vulnerability than CVE-2015-1676, CVE-2015-1677, CVE-2015-1678, and CVE-2015-1680.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-05-20T18:56:32">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-05-28T14:30:27.606-04:00">DRAFT</status_change>
            <status_change date="2015-06-15T04:00:18.464-04:00">INTERIM</status_change>
            <status_change date="2015-07-06T04:00:16.339-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Windows Server 2k3 and vulnerable file version">
          <criteria operator="OR" comment="Either OS">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of win32k.sys is less than 5.2.3790.5615" test_ref="oval:org.mitre.oval:tst:138664"/>
        </criteria>
        <criteria operator="AND" comment="Vista / 2k8 + vulnerable file version">
          <criteria operator="OR" comment="Vista / 2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:81723"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.0.6002.23680" test_ref="oval:org.mitre.oval:tst:138658"/>
            </criteria>
            <criterion comment="Check if the version of win32k.sys is less than 6.0.6002.19372" test_ref="oval:org.mitre.oval:tst:138686"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / R2 + vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.1.7601.23000" test_ref="oval:org.mitre.oval:tst:138862"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.23038" test_ref="oval:org.mitre.oval:tst:138649"/>
            </criteria>
            <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.18834" test_ref="oval:org.mitre.oval:tst:138724"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8/2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:115678"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.21457" test_ref="oval:org.mitre.oval:tst:138582"/>
            </criteria>
            <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.17343" test_ref="oval:org.mitre.oval:tst:138343"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1 / 2K12 R2and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of win32k.sys is less than 6.3.9600.17796" test_ref="oval:org.mitre.oval:tst:138198"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28554" version="6" class="vulnerability">
      <metadata>
        <title>Windows Telnet service buffer overflow vulnerability - CVE-2015-0014 (MS15-002)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-0014" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0014"/>
        <description>Buffer overflow in the Telnet service in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 allows remote attackers to execute arbitrary code via crafted packets, aka "Windows Telnet Service Buffer Overflow Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-01-16T08:40:43">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-01-16T19:08:23.374-05:00">DRAFT</status_change>
            <status_change date="2015-02-02T04:00:30.935-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:43110 - bulletins for the month of February 2015" date="2015-02-16T13:18:00.755-05:00">
              <contributor organization="SecPod Technologies">Kumarswamy S</contributor>
            </modified>
            <status_change date="2015-03-09T04:01:45.127-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:137241 - obj:43110 checks scesrv.dll but should check tlntsess.exe. New object checks correct filename." date="2015-03-24T12:05:00.907-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-03-24T12:07:29.845-04:00">INTERIM</status_change>
            <status_change date="2015-04-13T04:00:18.346-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Windows Server 2k3 and vulnerable file version">
          <criteria operator="OR" comment="Either OS">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of Tlntsess.exe is less than 5.2.3790.5491" test_ref="oval:org.mitre.oval:tst:137350"/>
        </criteria>
        <criteria operator="AND" comment="Vista / 2k8 + vulnerable file version">
          <criteria operator="OR" comment="Vista / 2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of Tlntsess.exe is less than 6.0.6002.23557" test_ref="oval:org.mitre.oval:tst:136633"/>
              <criterion comment="Check if the version of Tlntsess.exe is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:136835"/>
            </criteria>
            <criterion comment="Check if the version of Tlntsess.exe is less than 6.0.6002.19250" test_ref="oval:org.mitre.oval:tst:137168"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / R2 + vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of Tlntsess.exe is less than 6.1.7601.22893" test_ref="oval:org.mitre.oval:tst:137549"/>
              <criterion comment="Check if the version of Tlntsess.exe is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:137241"/>
            </criteria>
            <criterion comment="Check if the version of Tlntsess.exe is less than 6.1.7601.18685" test_ref="oval:org.mitre.oval:tst:137409"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8/2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of Tlntsess.exe is less than 6.2.9200.21315" test_ref="oval:org.mitre.oval:tst:137104"/>
              <criterion comment="Check if the version of Tlntsess.exe is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:137303"/>
            </criteria>
            <criterion comment="Check if the version of Tlntsess.exe is less than 6.2.9200.17198" test_ref="oval:org.mitre.oval:tst:137527"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1 / 2K12 R2and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of Tlntsess.exe is less than 6.3.9600.17547" test_ref="oval:org.mitre.oval:tst:137521"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28549" version="3" class="vulnerability">
      <metadata>
        <title>Adobe font driver information disclosure vulnerability - CVE-2015-0089 (MS15-021)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-0089" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0089"/>
        <description>Adobe Font Driver in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to obtain sensitive information from kernel memory, and possibly bypass the KASLR protection mechanism, via a crafted font, aka "Adobe Font Driver Information Disclosure Vulnerability," a different vulnerability than CVE-2015-0087.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-03-16T10:01:42">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-03-17T10:44:56.363-04:00">DRAFT</status_change>
            <status_change date="2015-04-06T04:00:08.779-04:00">INTERIM</status_change>
            <status_change date="2015-04-27T04:00:15.975-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Server 2k3 and vulnerable file version">
          <criteria operator="OR" comment="2k3 (x86/x64/ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of atmfd.dll is less than 5.2.2.241" test_ref="oval:org.mitre.oval:tst:138235"/>
        </criteria>
        <criteria operator="AND" comment="Vista/2k8/Win7/2k8 R2/ Win 8/2k12/Win 8.1/2k12 R2 and vulnerable file version">
          <criteria operator="OR" comment="Vista/2k8/Win7/2k8 R2/ Win 8/2k12/Win 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of atmfd.dll is less than 5.1.2.241" test_ref="oval:org.mitre.oval:tst:137787"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28540" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-0021 (MS15-009)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 6</product>
        </affected>
        <reference ref_id="CVE-2015-0021" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0021" source="CVE"/>
        <description>Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-02-13T10:59:59">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-02-16T13:12:09.943-05:00">DRAFT</status_change>
            <status_change date="2015-03-09T04:01:44.434-04:00">INTERIM</status_change>
            <status_change date="2015-03-30T04:00:19.273-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5508" test_ref="oval:org.mitre.oval:tst:137925"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21432" test_ref="oval:org.mitre.oval:tst:138027"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista / 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19281" test_ref="oval:org.mitre.oval:tst:138002"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23590" test_ref="oval:org.mitre.oval:tst:137924"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23644" test_ref="oval:org.mitre.oval:tst:137686"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19600" test_ref="oval:org.mitre.oval:tst:137706"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23655" test_ref="oval:org.mitre.oval:tst:137677"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18715" test_ref="oval:org.mitre.oval:tst:138039"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22921" test_ref="oval:org.mitre.oval:tst:137991"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16609" test_ref="oval:org.mitre.oval:tst:138073"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20725" test_ref="oval:org.mitre.oval:tst:137846"/>
            </criteria>
            <criterion comment="Check if the version of Jscript9.dll is less than 9.0.8112.16620" test_ref="oval:org.mitre.oval:tst:137873"/>
            <criteria operator="AND" comment="Jscript and LDR">
              <criterion comment="Check if the version of Jscript9.dll is less than 9.0.8112.20730" test_ref="oval:org.mitre.oval:tst:137974"/>
              <criterion comment="Check if the version of Jscript9.dll is greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:137868"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <criteria operator="AND" comment="Win 7/R2">
              <criteria operator="OR" comment="Win 7/R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17229" test_ref="oval:org.mitre.oval:tst:137987"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21345" test_ref="oval:org.mitre.oval:tst:137107"/>
                </criteria>
                <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.17241" test_ref="oval:org.mitre.oval:tst:137700"/>
                <criteria operator="AND" comment="Jscript.dll and LDR">
                  <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.21359" test_ref="oval:org.mitre.oval:tst:137021"/>
                  <criterion comment="Check if the version of Jscript9.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:137516"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 8/ 2012 R2">
              <criteria operator="OR" comment="Win 8/ 2012">
                <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
                <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
                <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17228" test_ref="oval:org.mitre.oval:tst:137876"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21345" test_ref="oval:org.mitre.oval:tst:137107"/>
                </criteria>
                <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.17241" test_ref="oval:org.mitre.oval:tst:137700"/>
                <criteria operator="AND" comment="Jscript.dll and LDR">
                  <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.21359" test_ref="oval:org.mitre.oval:tst:137021"/>
                  <criterion comment="Check if the version of Jscript9.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:137516"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28530" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-1731 (MS15-056)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-1731" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1731" source="CVE"/>
        <description>Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-1736, CVE-2015-1737, and CVE-2015-1755.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-16T04:41:39">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-06-18T10:14:17.220-04:00">DRAFT</status_change>
            <status_change date="2015-07-06T04:00:15.745-04:00">INTERIM</status_change>
            <status_change date="2015-07-27T04:00:20.022-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17377" test_ref="oval:org.mitre.oval:tst:139004"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21489" test_ref="oval:org.mitre.oval:tst:138844"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17842" test_ref="oval:org.mitre.oval:tst:138937"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28529" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-2401 (MS15-065)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-2401" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2401" source="CVE"/>
        <description>Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-1767 and CVE-2015-2408.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-07-22T13:00:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-07-23T11:16:20.056-04:00">DRAFT</status_change>
            <status_change date="2015-08-10T04:00:33.970-04:00">INTERIM</status_change>
            <status_change date="2015-08-31T04:00:04.569-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16669" test_ref="oval:org.mitre.oval:tst:141203"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20784" test_ref="oval:org.mitre.oval:tst:141111"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17412" test_ref="oval:org.mitre.oval:tst:140758"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21523" test_ref="oval:org.mitre.oval:tst:141225"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17905" test_ref="oval:org.mitre.oval:tst:141110"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28525" version="3" class="vulnerability">
      <metadata>
        <title>Windows LoadLibrary EoP vulnerability - CVE-2015-1758 (MS15-063)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-1758" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1758"/>
        <description>Untrusted search path vulnerability in the LoadLibrary function in the kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT allows local users to gain privileges via a Trojan horse DLL in an unspecified directory, aka "Windows LoadLibrary EoP Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-16T00:37:48">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-06-22T14:09:02.047-04:00">DRAFT</status_change>
            <status_change date="2015-07-13T04:00:10.021-04:00">INTERIM</status_change>
            <status_change date="2015-08-03T04:01:48.959-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vista / 2k8 + vulnerable file version">
          <criteria operator="OR" comment="Vista / 2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="LDR/GDR">
            <criterion comment="Check if the version of kernel32.dll is less than 6.0.6002.19381" test_ref="oval:org.mitre.oval:tst:139077"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of kernel32.dll is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:113560"/>
              <criterion comment="Check if the version of kernel32.dll is less than 6.0.6002.23688" test_ref="oval:org.mitre.oval:tst:139079"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / R2 SP1 + vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2 SP1">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="Check for LDR/GDR">
            <criterion comment="Check if the version of kernel32.dll is less than 6.1.7601.18847" test_ref="oval:org.mitre.oval:tst:138212"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of kernel32.dll is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:113836"/>
              <criterion comment="Check if the version of kernel32.dll is less than 6.1.7601.23049" test_ref="oval:org.mitre.oval:tst:138094"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8 / 2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of kernelbase.dll is less than 6.2.9200.17366" test_ref="oval:org.mitre.oval:tst:139013"/>
            <criteria operator="AND" comment="Check for LDR range">
              <criterion comment="Check if the version of kernelbase.dll is greater than or equal to 6.2.9200.20000" test_ref="oval:org.mitre.oval:tst:138812"/>
              <criterion comment="Check if the version of kernelbase.dll is less than 6.2.9200.21478" test_ref="oval:org.mitre.oval:tst:138822"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28523" version="3" class="vulnerability">
      <metadata>
        <title>Microsoft SharePoint XSS vulnerability – CVE-2015-1653 (MS15-036)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft SharePoint Foundation 2013</product>
          <product>Microsoft SharePoint Server 2013</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-1653" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1653"/>
        <description>Cross-site scripting (XSS) vulnerability in Microsoft SharePoint Foundation 2013 SP1 and SharePoint Server 2013 SP1 allows remote attackers to inject arbitrary web script or HTML via a crafted request, aka "Microsoft SharePoint XSS Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-04-21T14:12:20">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-04-24T09:26:54.953-04:00">DRAFT</status_change>
            <status_change date="2015-05-11T04:00:14.929-04:00">INTERIM</status_change>
            <status_change date="2015-06-01T04:00:17.114-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="Check if the version of Microsoft.Office.Server.Search.dll is less than 15.0.4711.1000" test_ref="oval:org.mitre.oval:tst:137998"/>
        <criteria operator="OR" comment="Either SharePoint Server 2013 / SharePoint Foundation 2013">
          <extend_definition comment="Microsoft SharePoint Server 2013 is installed" definition_ref="oval:org.mitre.oval:def:16325"/>
          <extend_definition comment="Microsoft SharePoint Foundation 2013 is installed" definition_ref="oval:org.mitre.oval:def:19090"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28522" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-0046 (MS15-009)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-0046" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0046" source="CVE"/>
        <description>Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-0038 and CVE-2015-0042.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-02-13T10:59:59">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-02-16T13:11:10.809-05:00">DRAFT</status_change>
            <status_change date="2015-03-09T04:01:44.035-04:00">INTERIM</status_change>
            <status_change date="2015-03-30T04:00:18.977-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16609" test_ref="oval:org.mitre.oval:tst:138073"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20725" test_ref="oval:org.mitre.oval:tst:137846"/>
            </criteria>
            <criterion comment="Check if the version of Jscript9.dll is less than 9.0.8112.16620" test_ref="oval:org.mitre.oval:tst:137873"/>
            <criteria operator="AND" comment="Jscript and LDR">
              <criterion comment="Check if the version of Jscript9.dll is less than 9.0.8112.20730" test_ref="oval:org.mitre.oval:tst:137974"/>
              <criterion comment="Check if the version of Jscript9.dll is greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:137868"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <criteria operator="AND" comment="Win 7/R2">
              <criteria operator="OR" comment="Win 7/R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17229" test_ref="oval:org.mitre.oval:tst:137987"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21345" test_ref="oval:org.mitre.oval:tst:137107"/>
                </criteria>
                <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.17241" test_ref="oval:org.mitre.oval:tst:137700"/>
                <criteria operator="AND" comment="Jscript.dll and LDR">
                  <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.21359" test_ref="oval:org.mitre.oval:tst:137021"/>
                  <criterion comment="Check if the version of Jscript9.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:137516"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 8/ 2012 R2">
              <criteria operator="OR" comment="Win 8/ 2012">
                <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
                <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
                <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17228" test_ref="oval:org.mitre.oval:tst:137876"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21345" test_ref="oval:org.mitre.oval:tst:137107"/>
                </criteria>
                <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.17241" test_ref="oval:org.mitre.oval:tst:137700"/>
                <criteria operator="AND" comment="Jscript.dll and LDR">
                  <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.21359" test_ref="oval:org.mitre.oval:tst:137021"/>
                  <criterion comment="Check if the version of Jscript9.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:137516"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/ 2k12 R2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7/ 2k8 R2/ 8.1/ 2k12 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criteria operator="OR" comment="either file">
                <criterion comment="Check if the version of Jscript9.dll is less than 11.0.9600.17640" test_ref="oval:org.mitre.oval:tst:137882"/>
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17631" test_ref="oval:org.mitre.oval:tst:137835"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28518" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-1745 (MS15-056)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-1745" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1745" source="CVE"/>
        <description>Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-1735, CVE-2015-1740, CVE-2015-1744, and CVE-2015-1766.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-16T04:41:39">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-06-18T10:14:38.870-04:00">DRAFT</status_change>
            <status_change date="2015-07-06T04:00:15.409-04:00">INTERIM</status_change>
            <status_change date="2015-07-27T04:00:19.132-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5624" test_ref="oval:org.mitre.oval:tst:138803"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21466" test_ref="oval:org.mitre.oval:tst:138892"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista / 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19383" test_ref="oval:org.mitre.oval:tst:138665"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23690" test_ref="oval:org.mitre.oval:tst:139050"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23687" test_ref="oval:org.mitre.oval:tst:138276"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19632" test_ref="oval:org.mitre.oval:tst:138942"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23687" test_ref="oval:org.mitre.oval:tst:138276"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18870" test_ref="oval:org.mitre.oval:tst:138751"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.23073" test_ref="oval:org.mitre.oval:tst:138584"/>
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.23000" test_ref="oval:org.mitre.oval:tst:138202"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16659" test_ref="oval:org.mitre.oval:tst:138475"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20774" test_ref="oval:org.mitre.oval:tst:138843"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17377" test_ref="oval:org.mitre.oval:tst:139004"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21489" test_ref="oval:org.mitre.oval:tst:138844"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17842" test_ref="oval:org.mitre.oval:tst:138937"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28517" version="3" class="vulnerability">
      <metadata>
        <title>Windows Journal remote code execution vulnerability - CVE-2015-1695 (MS15-045)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-1695" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1695"/>
        <description>Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allow remote attackers to execute arbitrary code via a crafted Journal file, aka "Windows Journal Remote Code Execution Vulnerability," a different vulnerability than CVE-2015-1675, CVE-2015-1696, CVE-2015-1697, CVE-2015-1698, and CVE-2015-1699.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-05-20T18:56:32">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-05-28T14:32:53.501-04:00">DRAFT</status_change>
            <status_change date="2015-06-15T04:00:17.873-04:00">INTERIM</status_change>
            <status_change date="2015-07-06T04:00:15.156-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vista / 2k8 + vulnerable file version">
          <criteria operator="OR" comment="Vista / 2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Journal.dll is less than 6.0.6002.23664" test_ref="oval:org.mitre.oval:tst:138166"/>
              <criterion comment="Check if the version of Journal.dll is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:138660"/>
            </criteria>
            <criterion comment="Check if the version of Journal.dll is less than 6.0.6002.19356" test_ref="oval:org.mitre.oval:tst:138728"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / R2 + vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Journal.dll is less than 6.1.7601.23020" test_ref="oval:org.mitre.oval:tst:138830"/>
              <criterion comment="Check if the version of Journal.dll is greater than or equal to 6.1.7601.23000" test_ref="oval:org.mitre.oval:tst:138508"/>
            </criteria>
            <criterion comment="Check if the version of Journal.dll is less than 6.1.7601.18815" test_ref="oval:org.mitre.oval:tst:138819"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8/2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Journal.dll is less than 6.2.9200.21444" test_ref="oval:org.mitre.oval:tst:138174"/>
              <criterion comment="Check if the version of Journal.dll is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:138277"/>
            </criteria>
            <criterion comment="Check if the version of Journal.dll is less than 6.2.9200.17330" test_ref="oval:org.mitre.oval:tst:138698"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1 / 2K12 R2and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of Journal.dll is less than 6.3.9600.17793" test_ref="oval:org.mitre.oval:tst:138477"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28512" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-1752 (MS15-056)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-1752" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1752" source="CVE"/>
        <description>Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-1741.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-16T04:41:39">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-06-18T10:14:22.424-04:00">DRAFT</status_change>
            <status_change date="2015-07-06T04:00:14.532-04:00">INTERIM</status_change>
            <status_change date="2015-07-27T04:00:17.799-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16659" test_ref="oval:org.mitre.oval:tst:138475"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20774" test_ref="oval:org.mitre.oval:tst:138843"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17377" test_ref="oval:org.mitre.oval:tst:139004"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21489" test_ref="oval:org.mitre.oval:tst:138844"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17842" test_ref="oval:org.mitre.oval:tst:138937"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28487" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-1625 (MS15-018)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-1625" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1625" source="CVE"/>
        <description>Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-1634.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-03-16T09:23:57">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-03-17T10:36:44.815-04:00">DRAFT</status_change>
            <status_change date="2015-04-06T04:00:08.014-04:00">INTERIM</status_change>
            <status_change date="2015-04-27T04:00:15.225-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5543" test_ref="oval:org.mitre.oval:tst:138082"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21443" test_ref="oval:org.mitre.oval:tst:137862"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista / 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19310" test_ref="oval:org.mitre.oval:tst:138155"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23620" test_ref="oval:org.mitre.oval:tst:138114"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23661" test_ref="oval:org.mitre.oval:tst:138196"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19607" test_ref="oval:org.mitre.oval:tst:138058"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23661" test_ref="oval:org.mitre.oval:tst:138196"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18751" test_ref="oval:org.mitre.oval:tst:137478"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22958" test_ref="oval:org.mitre.oval:tst:138221"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16633" test_ref="oval:org.mitre.oval:tst:137971"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20747" test_ref="oval:org.mitre.oval:tst:137783"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17267" test_ref="oval:org.mitre.oval:tst:138160"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21384" test_ref="oval:org.mitre.oval:tst:138199"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17690" test_ref="oval:org.mitre.oval:tst:138148"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28475" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-0035 (MS15-009)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-0035" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0035" source="CVE"/>
        <description>Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-0027, CVE-2015-0039, CVE-2015-0052, and CVE-2015-0068.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-02-13T10:59:59">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-02-16T13:11:13.068-05:00">DRAFT</status_change>
            <status_change date="2015-03-09T04:01:43.016-04:00">INTERIM</status_change>
            <status_change date="2015-03-30T04:00:18.175-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <criteria operator="AND" comment="Win 7/R2">
              <criteria operator="OR" comment="Win 7/R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17229" test_ref="oval:org.mitre.oval:tst:137987"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21345" test_ref="oval:org.mitre.oval:tst:137107"/>
                </criteria>
                <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.17241" test_ref="oval:org.mitre.oval:tst:137700"/>
                <criteria operator="AND" comment="Jscript.dll and LDR">
                  <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.21359" test_ref="oval:org.mitre.oval:tst:137021"/>
                  <criterion comment="Check if the version of Jscript9.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:137516"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 8/ 2012 R2">
              <criteria operator="OR" comment="Win 8/ 2012">
                <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
                <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
                <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17228" test_ref="oval:org.mitre.oval:tst:137876"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21345" test_ref="oval:org.mitre.oval:tst:137107"/>
                </criteria>
                <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.17241" test_ref="oval:org.mitre.oval:tst:137700"/>
                <criteria operator="AND" comment="Jscript.dll and LDR">
                  <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.21359" test_ref="oval:org.mitre.oval:tst:137021"/>
                  <criterion comment="Check if the version of Jscript9.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:137516"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/ 2k12 R2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7/ 2k8 R2/ 8.1/ 2k12 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criteria operator="OR" comment="either file">
                <criterion comment="Check if the version of Jscript9.dll is less than 11.0.9600.17640" test_ref="oval:org.mitre.oval:tst:137882"/>
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17631" test_ref="oval:org.mitre.oval:tst:137835"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28469" version="3" class="vulnerability">
      <metadata>
        <title>Adobe font driver information disclosure vulnerability - CVE-2015-0087 (MS15-021)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-0087" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0087"/>
        <description>Adobe Font Driver in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to obtain sensitive information from kernel memory, and possibly bypass the KASLR protection mechanism, via a crafted font, aka "Adobe Font Driver Information Disclosure Vulnerability," a different vulnerability than CVE-2015-0089.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-03-16T10:01:42">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-03-17T10:44:48.840-04:00">DRAFT</status_change>
            <status_change date="2015-04-06T04:00:07.774-04:00">INTERIM</status_change>
            <status_change date="2015-04-27T04:00:14.737-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Server 2k3 and vulnerable file version">
          <criteria operator="OR" comment="2k3 (x86/x64/ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of atmfd.dll is less than 5.2.2.241" test_ref="oval:org.mitre.oval:tst:138235"/>
        </criteria>
        <criteria operator="AND" comment="Vista/2k8/Win7/2k8 R2/ Win 8/2k12/Win 8.1/2k12 R2 and vulnerable file version">
          <criteria operator="OR" comment="Vista/2k8/Win7/2k8 R2/ Win 8/2k12/Win 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of atmfd.dll is less than 5.1.2.241" test_ref="oval:org.mitre.oval:tst:137787"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28464" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-0099 (MS15-018)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <product>Microsoft Internet Explorer 10</product>
        </affected>
        <reference ref_id="CVE-2015-0099" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0099" source="CVE"/>
        <description>Microsoft Internet Explorer 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-03-16T09:23:57">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-03-17T10:36:33.444-04:00">DRAFT</status_change>
            <status_change date="2015-04-06T04:00:07.539-04:00">INTERIM</status_change>
            <status_change date="2015-04-27T04:00:14.389-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
        <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
          <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
          <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
          <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
          <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
          <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
        </criteria>
        <criteria operator="OR" comment="Check for vulnerable versions">
          <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17267" test_ref="oval:org.mitre.oval:tst:138160"/>
          <criteria operator="AND" comment="Check for LDR">
            <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21384" test_ref="oval:org.mitre.oval:tst:138199"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28449" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer ASLR bypass vulnerability - CVE-2015-0069 (MS15-009)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-0069" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0069" source="CVE"/>
        <description>Microsoft Internet Explorer 10 and 11 allows remote attackers to bypass the ASLR protection mechanism via a crafted web site, aka "Internet Explorer ASLR Bypass Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-02-13T10:59:59">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-02-16T13:11:46.039-05:00">DRAFT</status_change>
            <status_change date="2015-03-09T04:01:41.636-04:00">INTERIM</status_change>
            <status_change date="2015-03-30T04:00:17.949-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <criteria operator="AND" comment="Win 7/R2">
              <criteria operator="OR" comment="Win 7/R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17229" test_ref="oval:org.mitre.oval:tst:137987"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21345" test_ref="oval:org.mitre.oval:tst:137107"/>
                </criteria>
                <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.17241" test_ref="oval:org.mitre.oval:tst:137700"/>
                <criteria operator="AND" comment="Jscript.dll and LDR">
                  <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.21359" test_ref="oval:org.mitre.oval:tst:137021"/>
                  <criterion comment="Check if the version of Jscript9.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:137516"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 8/ 2012 R2">
              <criteria operator="OR" comment="Win 8/ 2012">
                <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
                <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
                <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17228" test_ref="oval:org.mitre.oval:tst:137876"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21345" test_ref="oval:org.mitre.oval:tst:137107"/>
                </criteria>
                <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.17241" test_ref="oval:org.mitre.oval:tst:137700"/>
                <criteria operator="AND" comment="Jscript.dll and LDR">
                  <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.21359" test_ref="oval:org.mitre.oval:tst:137021"/>
                  <criterion comment="Check if the version of Jscript9.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:137516"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/ 2k12 R2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7/ 2k8 R2/ 8.1/ 2k12 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criteria operator="OR" comment="either file">
                <criterion comment="Check if the version of Jscript9.dll is less than 11.0.9600.17640" test_ref="oval:org.mitre.oval:tst:137882"/>
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17631" test_ref="oval:org.mitre.oval:tst:137835"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28429" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer information disclosure vulnerability - CVE-2015-1765 (MS15-056)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-1765" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1765" source="CVE"/>
        <description>Microsoft Internet Explorer 9 through 11 allows remote attackers to read the browser history via a crafted web site.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-16T04:41:39">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-06-18T10:14:40.483-04:00">DRAFT</status_change>
            <status_change date="2015-07-06T04:00:12.948-04:00">INTERIM</status_change>
            <status_change date="2015-07-27T04:00:15.885-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16659" test_ref="oval:org.mitre.oval:tst:138475"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20774" test_ref="oval:org.mitre.oval:tst:138843"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17377" test_ref="oval:org.mitre.oval:tst:139004"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21489" test_ref="oval:org.mitre.oval:tst:138844"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17842" test_ref="oval:org.mitre.oval:tst:138937"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28428" version="3" class="vulnerability">
      <metadata>
        <title>Malformed PNG parsing information disclosure vulnerability - CVE-2015-0080 (MS15-024)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Vista</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-0080" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0080"/>
        <description>Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 do not properly initialize memory for rendering of malformed PNG images, which allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Malformed PNG Parsing Information Disclosure Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-03-16T09:23:57">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-03-17T11:15:02.927-04:00">DRAFT</status_change>
            <status_change date="2015-04-06T04:00:06.923-04:00">INTERIM</status_change>
            <status_change date="2015-04-27T04:00:13.919-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Check for Windows Server 2003 x86/x64 and vulnerable file version">
          <criteria operator="OR" comment="Check for Windows Server 2003 x86/x64">
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of gdiplus.dll is less than 5.2.6002.23609" test_ref="oval:org.mitre.oval:tst:138297"/>
        </criteria>
        <criteria operator="AND" comment="Vista / 2k8 + vulnerable file version">
          <criteria operator="OR" comment="Vista / 2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="Check for LDR/GDR">
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of windowscodecs.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:135896"/>
              <criterion comment="Check if the version of Windowscodecs.dll is less than 7.0.6002.23609" test_ref="oval:org.mitre.oval:tst:137953"/>
            </criteria>
            <criterion comment="Check if the version of Windowscodecs.dll is less than 7.0.6002.19299" test_ref="oval:org.mitre.oval:tst:138197"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / R2 + vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for LDR/GDR">
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of windowscodecs.dll is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:135899"/>
              <criterion comment="Check if the version of Windowscodecs.dll is less than 6.2.9200.21369" test_ref="oval:org.mitre.oval:tst:137896"/>
            </criteria>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of Windowscodecs.dll is less than 6.1.7601.22948" test_ref="oval:org.mitre.oval:tst:138144"/>
              <criterion comment="Check if the version of Windowscodecs.dll is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:137874"/>
            </criteria>
            <criteria operator="AND" comment="range to avoid FP">
              <criterion comment="Check if the version of Windowscodecs.dll is greater than or equal to 6.2.9200.00000" test_ref="oval:org.mitre.oval:tst:138207"/>
              <criterion comment="Check if the version of Windowscodecs.dll is less than 6.2.9200.17251" test_ref="oval:org.mitre.oval:tst:138224"/>
            </criteria>
            <criterion comment="Check if the version of Windowscodecs.dll is less than 6.1.7601.18741" test_ref="oval:org.mitre.oval:tst:137778"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Windows 2008 R2 IA64">
          <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          <criteria operator="OR" comment="either file versions">
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of Windowscodecs.dll is less than 6.1.7601.22948" test_ref="oval:org.mitre.oval:tst:138144"/>
              <criterion comment="Check if the version of Windowscodecs.dll is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:137874"/>
            </criteria>
            <criterion comment="Check if the version of Windowscodecs.dll is less than 6.1.7601.18741" test_ref="oval:org.mitre.oval:tst:137778"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8/2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of windowscodecs.dll is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:135899"/>
              <criterion comment="Check if the version of Windowscodecs.dll is less than 6.2.9200.21369" test_ref="oval:org.mitre.oval:tst:137896"/>
            </criteria>
            <criterion comment="Check if the version of Windowscodecs.dll is less than 6.2.9200.17251" test_ref="oval:org.mitre.oval:tst:138224"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1 / 2K12 R2and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of Windowscodecs.dll is less than 6.3.9600.17669" test_ref="oval:org.mitre.oval:tst:138402"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28425" version="3" class="vulnerability">
      <metadata>
        <title>Outlook Web App token spoofing vulnerability (CVE-2014-6319) - MS14-075</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Exchange Server 2007</product>
          <product>Microsoft Exchange Server 2010</product>
          <product>Microsoft Exchange Server 2013</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-6319" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6319"/>
        <description>Outlook Web App (OWA) in Microsoft Exchange Server 2007 SP3, 2010 SP3, and 2013 SP1 and Cumulative Update 6 does not properly validate tokens in requests, which allows remote attackers to spoof the origin of e-mail messages via unspecified vectors, aka "Outlook Web App Token Spoofing Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-12-12T15:06:06">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-12-15T23:58:20.948-05:00">DRAFT</status_change>
            <status_change date="2015-01-05T04:00:40.958-05:00">INTERIM</status_change>
            <status_change date="2015-01-26T04:00:43.811-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Exchange Server 2007 and vulnerable file version">
          <extend_definition comment="Microsoft Exchange Server 2007 (no Service Pack) is installed" definition_ref="oval:org.mitre.oval:def:1641"/>
          <criterion comment="Check if the version of exsetup.exe is less than 8.03.0389.002" test_ref="oval:org.mitre.oval:tst:135507"/>
        </criteria>
        <criteria operator="AND" comment="Exchange Server 2010 and vulnerable file version">
          <extend_definition comment="Microsoft Exchange Server 2010 is installed" definition_ref="oval:org.mitre.oval:def:15107"/>
          <criterion comment="Check if the version of ExSetup.exe is less than 14.03.0224.001" test_ref="oval:org.mitre.oval:tst:135743"/>
        </criteria>
        <criteria operator="AND" comment="Exchange Server 2013 and vulnerable file version">
          <extend_definition comment="Microsoft Exchange Server 2013 is installed" definition_ref="oval:org.mitre.oval:def:18626"/>
          <criterion comment="Check if the version of ExSetup.exe is less than 15.00.0847.035" test_ref="oval:org.mitre.oval:tst:135793"/>
        </criteria>
        <criteria operator="AND" comment="Exchange 2013 CU 6 and vulnerable file version">
          <criterion comment="Check if the version of ExSetup.exe is less than 15.00.0995.034" test_ref="oval:org.mitre.oval:tst:135701"/>
          <extend_definition comment="Microsoft Exchange Server 2013 CU 6 is installed" definition_ref="oval:org.mitre.oval:def:28213"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1641" version="5" class="inventory">
      <metadata>
        <title>Microsoft Exchange Server 2007 (no Service Pack) is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:exchange_server:2007:gold"/>
        <description>Exchange Server 2007 (no Service Pack) is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-05-09T10:04:48">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2007-05-09T12:53:06-04:00">DRAFT</status_change>
            <status_change date="2007-05-31T15:26:34.310-04:00">INTERIM</status_change>
            <status_change date="2007-06-15T11:07:35.112-04:00">ACCEPTED</status_change>
            <modified comment="set datatype to int" date="2007-10-25T16:45:00.621-04:00">
              <contributor organization="Opsware, Inc.">Jeff Cheng</contributor>
            </modified>
            <status_change date="2007-10-25T16:51:06.842-04:00">INTERIM</status_change>
            <status_change date="2007-11-13T12:01:00.696-05:00">ACCEPTED</status_change>
            <modified comment="The method it was using to check for lack of a service pack is not valid for Exchange 2007." date="2008-07-11T11:14:00.045-04:00">
              <contributor organization="Secure Elements, Inc.">Jeff Ito</contributor>
            </modified>
            <status_change date="2008-07-11T11:18:44.060-04:00">INTERIM</status_change>
            <status_change date="2008-07-28T04:00:05.662-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:1641 - Updated CPEs for Microsoft Exchange Server." date="2011-03-29T13:58:00.209-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-03-29T13:58:54.126-04:00">INTERIM</status_change>
            <status_change date="2011-04-18T04:00:33.435-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="Exchange Server 2007 is installed." test_ref="oval:org.mitre.oval:tst:8521"/>
        <criterion comment="No Exchange Server 2007 SP is installed." test_ref="oval:org.mitre.oval:tst:8498"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:15107" version="3" class="inventory">
      <metadata>
        <title>Microsoft Exchange Server 2010 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <product>Microsoft Exchange Server 2010</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:exchange:2010"/>
        <description>Microsoft Exchange Server 2010 is installed</description>
        <oval_repository>
          <dates>
            <submitted date="2012-04-04T12:52:26.748+04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2012-04-06T11:34:21.490-04:00">DRAFT</status_change>
            <status_change date="2012-04-23T04:00:13.600-04:00">INTERIM</status_change>
            <status_change date="2012-05-14T04:00:06.829-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="Microsoft Exchange Server 2010 is installed" test_ref="oval:org.mitre.oval:tst:77602"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28415" version="3" class="vulnerability">
      <metadata>
        <title>Exchange URL redirection vulnerability (CVE-2014-6336) - MS14-075</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Exchange Server 2013</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-6336" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6336"/>
        <description>Outlook Web App (OWA) in Microsoft Exchange Server 2013 SP1 and Cumulative Update 6 does not properly validate redirection tokens, which allows remote attackers to redirect users to arbitrary web sites and spoof the origin of e-mail messages via unspecified vectors, aka "Exchange URL Redirection Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-12-12T15:06:06">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-12-15T23:58:17.070-05:00">DRAFT</status_change>
            <status_change date="2015-01-05T04:00:40.340-05:00">INTERIM</status_change>
            <status_change date="2015-01-26T04:00:42.997-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Exchange Server 2013 and vulnerable file version">
          <extend_definition comment="Microsoft Exchange Server 2013 is installed" definition_ref="oval:org.mitre.oval:def:18626"/>
          <criterion comment="Check if the version of ExSetup.exe is less than 15.00.0847.035" test_ref="oval:org.mitre.oval:tst:135793"/>
        </criteria>
        <criteria operator="AND" comment="Exchange 2013 CU 6 and vulnerable file version">
          <criterion comment="Check if the version of ExSetup.exe is less than 15.00.0995.034" test_ref="oval:org.mitre.oval:tst:135701"/>
          <extend_definition comment="Microsoft Exchange Server 2013 CU 6 is installed" definition_ref="oval:org.mitre.oval:def:28213"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28413" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-0036 (MS15-009)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
          <product>Microsoft Internet Explorer 6</product>
        </affected>
        <reference ref_id="CVE-2015-0036" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0036" source="CVE"/>
        <description>Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-0017, CVE-2015-0020, CVE-2015-0022, CVE-2015-0026, CVE-2015-0030, CVE-2015-0031, and CVE-2015-0041.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-02-13T10:59:59">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-02-16T13:11:20.496-05:00">DRAFT</status_change>
            <status_change date="2015-03-09T04:01:40.043-04:00">INTERIM</status_change>
            <status_change date="2015-03-30T04:00:17.603-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5508" test_ref="oval:org.mitre.oval:tst:137925"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21432" test_ref="oval:org.mitre.oval:tst:138027"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista / 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19281" test_ref="oval:org.mitre.oval:tst:138002"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23590" test_ref="oval:org.mitre.oval:tst:137924"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23644" test_ref="oval:org.mitre.oval:tst:137686"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19600" test_ref="oval:org.mitre.oval:tst:137706"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23655" test_ref="oval:org.mitre.oval:tst:137677"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18715" test_ref="oval:org.mitre.oval:tst:138039"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22921" test_ref="oval:org.mitre.oval:tst:137991"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16609" test_ref="oval:org.mitre.oval:tst:138073"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20725" test_ref="oval:org.mitre.oval:tst:137846"/>
            </criteria>
            <criterion comment="Check if the version of Jscript9.dll is less than 9.0.8112.16620" test_ref="oval:org.mitre.oval:tst:137873"/>
            <criteria operator="AND" comment="Jscript and LDR">
              <criterion comment="Check if the version of Jscript9.dll is less than 9.0.8112.20730" test_ref="oval:org.mitre.oval:tst:137974"/>
              <criterion comment="Check if the version of Jscript9.dll is greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:137868"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <criteria operator="AND" comment="Win 7/R2">
              <criteria operator="OR" comment="Win 7/R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17229" test_ref="oval:org.mitre.oval:tst:137987"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21345" test_ref="oval:org.mitre.oval:tst:137107"/>
                </criteria>
                <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.17241" test_ref="oval:org.mitre.oval:tst:137700"/>
                <criteria operator="AND" comment="Jscript.dll and LDR">
                  <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.21359" test_ref="oval:org.mitre.oval:tst:137021"/>
                  <criterion comment="Check if the version of Jscript9.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:137516"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 8/ 2012 R2">
              <criteria operator="OR" comment="Win 8/ 2012">
                <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
                <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
                <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17228" test_ref="oval:org.mitre.oval:tst:137876"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21345" test_ref="oval:org.mitre.oval:tst:137107"/>
                </criteria>
                <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.17241" test_ref="oval:org.mitre.oval:tst:137700"/>
                <criteria operator="AND" comment="Jscript.dll and LDR">
                  <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.21359" test_ref="oval:org.mitre.oval:tst:137021"/>
                  <criterion comment="Check if the version of Jscript9.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:137516"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/ 2k12 R2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7/ 2k8 R2/ 8.1/ 2k12 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criteria operator="OR" comment="either file">
                <criterion comment="Check if the version of Jscript9.dll is less than 11.0.9600.17640" test_ref="oval:org.mitre.oval:tst:137882"/>
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17631" test_ref="oval:org.mitre.oval:tst:137835"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28405" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-1710 (MS15-043)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-1710" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1710" source="CVE"/>
        <description>Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-1694.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-05-20T08:43:05">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-05-28T14:16:33.151-04:00">DRAFT</status_change>
            <status_change date="2015-06-15T04:00:16.775-04:00">INTERIM</status_change>
            <status_change date="2015-07-06T04:00:12.369-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5602" test_ref="oval:org.mitre.oval:tst:138124"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21455" test_ref="oval:org.mitre.oval:tst:138315"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista / 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19367" test_ref="oval:org.mitre.oval:tst:137942"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23675" test_ref="oval:org.mitre.oval:tst:138544"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23676" test_ref="oval:org.mitre.oval:tst:138485"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19621" test_ref="oval:org.mitre.oval:tst:138412"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23676" test_ref="oval:org.mitre.oval:tst:138485"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18835" test_ref="oval:org.mitre.oval:tst:138592"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.23038" test_ref="oval:org.mitre.oval:tst:137853"/>
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.23000" test_ref="oval:org.mitre.oval:tst:138202"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16644" test_ref="oval:org.mitre.oval:tst:138514"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20758" test_ref="oval:org.mitre.oval:tst:138561"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17357" test_ref="oval:org.mitre.oval:tst:138213"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21470" test_ref="oval:org.mitre.oval:tst:138585"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17801" test_ref="oval:org.mitre.oval:tst:138184"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28401" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2014-6374 (MS14-080)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
          <product>Microsoft Internet Explorer 6</product>
        </affected>
        <reference ref_id="CVE-2014-6374" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6374" source="CVE"/>
        <description>Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-12-12T10:59:59">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-12-16T00:09:53.859-05:00">DRAFT</status_change>
            <status_change date="2015-01-05T04:00:38.903-05:00">INTERIM</status_change>
            <status_change date="2015-01-26T04:00:41.500-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5467" test_ref="oval:org.mitre.oval:tst:135844"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21420" test_ref="oval:org.mitre.oval:tst:135838"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista / 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19221" test_ref="oval:org.mitre.oval:tst:135689"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23528" test_ref="oval:org.mitre.oval:tst:135126"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23642" test_ref="oval:org.mitre.oval:tst:135810"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19587" test_ref="oval:org.mitre.oval:tst:135653"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23642" test_ref="oval:org.mitre.oval:tst:135810"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18667" test_ref="oval:org.mitre.oval:tst:135861"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22874" test_ref="oval:org.mitre.oval:tst:134963"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16599" test_ref="oval:org.mitre.oval:tst:135591"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20715" test_ref="oval:org.mitre.oval:tst:135879"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17183" test_ref="oval:org.mitre.oval:tst:135488"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21299" test_ref="oval:org.mitre.oval:tst:135770"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17496" test_ref="oval:org.mitre.oval:tst:135858"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28395" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-0023 (MS15-009)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <product>Microsoft Internet Explorer 10</product>
        </affected>
        <reference ref_id="CVE-2015-0023" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0023" source="CVE"/>
        <description>Microsoft Internet Explorer 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-0025.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-02-13T10:59:59">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-02-16T13:11:28.319-05:00">DRAFT</status_change>
            <status_change date="2015-03-09T04:01:39.658-04:00">INTERIM</status_change>
            <status_change date="2015-03-30T04:00:17.168-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
        <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
          <criteria operator="AND" comment="Win 7/R2">
            <criteria operator="OR" comment="Win 7/R2">
              <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
              <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
              <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            </criteria>
            <criteria operator="OR" comment="Check for vulnerable versions">
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17229" test_ref="oval:org.mitre.oval:tst:137987"/>
              <criteria operator="AND" comment="Check for LDR">
                <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
                <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21345" test_ref="oval:org.mitre.oval:tst:137107"/>
              </criteria>
              <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.17241" test_ref="oval:org.mitre.oval:tst:137700"/>
              <criteria operator="AND" comment="Jscript.dll and LDR">
                <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.21359" test_ref="oval:org.mitre.oval:tst:137021"/>
                <criterion comment="Check if the version of Jscript9.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:137516"/>
              </criteria>
            </criteria>
          </criteria>
          <criteria operator="AND" comment="Win 8/ 2012 R2">
            <criteria operator="OR" comment="Win 8/ 2012">
              <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
              <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
              <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
            </criteria>
            <criteria operator="OR" comment="Check for vulnerable versions">
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17228" test_ref="oval:org.mitre.oval:tst:137876"/>
              <criteria operator="AND" comment="Check for LDR">
                <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
                <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21345" test_ref="oval:org.mitre.oval:tst:137107"/>
              </criteria>
              <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.17241" test_ref="oval:org.mitre.oval:tst:137700"/>
              <criteria operator="AND" comment="Jscript.dll and LDR">
                <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.21359" test_ref="oval:org.mitre.oval:tst:137021"/>
                <criterion comment="Check if the version of Jscript9.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:137516"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28392" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2014-6373 (MS14-080)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <product>Microsoft Internet Explorer 10</product>
        </affected>
        <reference ref_id="CVE-2014-6373" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6373" source="CVE"/>
        <description>Microsoft Internet Explorer 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-12-12T10:59:59">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-12-16T00:10:03.090-05:00">DRAFT</status_change>
            <status_change date="2015-01-05T04:00:38.608-05:00">INTERIM</status_change>
            <status_change date="2015-01-26T04:00:41.183-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
        <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
          <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
          <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
          <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
          <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
          <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
        </criteria>
        <criteria operator="OR" comment="Check for vulnerable versions">
          <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17183" test_ref="oval:org.mitre.oval:tst:135488"/>
          <criteria operator="AND" comment="Check for LDR">
            <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21299" test_ref="oval:org.mitre.oval:tst:135770"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28390" version="3" class="vulnerability">
      <metadata>
        <title>Windows Journal remote code execution vulnerability - CVE-2015-1697 (MS15-045)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-1697" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1697"/>
        <description>Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allow remote attackers to execute arbitrary code via a crafted Journal file, aka "Windows Journal Remote Code Execution Vulnerability," a different vulnerability than CVE-2015-1675, CVE-2015-1695, CVE-2015-1696, CVE-2015-1698, and CVE-2015-1699.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-05-20T18:56:32">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-05-28T14:32:50.726-04:00">DRAFT</status_change>
            <status_change date="2015-06-15T04:00:16.394-04:00">INTERIM</status_change>
            <status_change date="2015-07-06T04:00:11.873-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vista / 2k8 + vulnerable file version">
          <criteria operator="OR" comment="Vista / 2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Journal.dll is less than 6.0.6002.23664" test_ref="oval:org.mitre.oval:tst:138166"/>
              <criterion comment="Check if the version of Journal.dll is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:138660"/>
            </criteria>
            <criterion comment="Check if the version of Journal.dll is less than 6.0.6002.19356" test_ref="oval:org.mitre.oval:tst:138728"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / R2 + vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Journal.dll is less than 6.1.7601.23020" test_ref="oval:org.mitre.oval:tst:138830"/>
              <criterion comment="Check if the version of Journal.dll is greater than or equal to 6.1.7601.23000" test_ref="oval:org.mitre.oval:tst:138508"/>
            </criteria>
            <criterion comment="Check if the version of Journal.dll is less than 6.1.7601.18815" test_ref="oval:org.mitre.oval:tst:138819"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8/2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Journal.dll is less than 6.2.9200.21444" test_ref="oval:org.mitre.oval:tst:138174"/>
              <criterion comment="Check if the version of Journal.dll is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:138277"/>
            </criteria>
            <criterion comment="Check if the version of Journal.dll is less than 6.2.9200.17330" test_ref="oval:org.mitre.oval:tst:138698"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1 / 2K12 R2and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of Journal.dll is less than 6.3.9600.17793" test_ref="oval:org.mitre.oval:tst:138477"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28383" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-0030 (MS15-009)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
          <product>Microsoft Internet Explorer 6</product>
        </affected>
        <reference ref_id="CVE-2015-0030" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0030" source="CVE"/>
        <description>Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-0017, CVE-2015-0020, CVE-2015-0022, CVE-2015-0026, CVE-2015-0031, CVE-2015-0036, and CVE-2015-0041.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-02-13T10:59:59">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-02-16T13:11:51.951-05:00">DRAFT</status_change>
            <status_change date="2015-03-09T04:01:38.664-04:00">INTERIM</status_change>
            <status_change date="2015-03-30T04:00:16.102-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5508" test_ref="oval:org.mitre.oval:tst:137925"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21432" test_ref="oval:org.mitre.oval:tst:138027"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista / 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19281" test_ref="oval:org.mitre.oval:tst:138002"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23590" test_ref="oval:org.mitre.oval:tst:137924"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23644" test_ref="oval:org.mitre.oval:tst:137686"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19600" test_ref="oval:org.mitre.oval:tst:137706"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23655" test_ref="oval:org.mitre.oval:tst:137677"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18715" test_ref="oval:org.mitre.oval:tst:138039"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22921" test_ref="oval:org.mitre.oval:tst:137991"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16609" test_ref="oval:org.mitre.oval:tst:138073"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20725" test_ref="oval:org.mitre.oval:tst:137846"/>
            </criteria>
            <criterion comment="Check if the version of Jscript9.dll is less than 9.0.8112.16620" test_ref="oval:org.mitre.oval:tst:137873"/>
            <criteria operator="AND" comment="Jscript and LDR">
              <criterion comment="Check if the version of Jscript9.dll is less than 9.0.8112.20730" test_ref="oval:org.mitre.oval:tst:137974"/>
              <criterion comment="Check if the version of Jscript9.dll is greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:137868"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <criteria operator="AND" comment="Win 7/R2">
              <criteria operator="OR" comment="Win 7/R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17229" test_ref="oval:org.mitre.oval:tst:137987"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21345" test_ref="oval:org.mitre.oval:tst:137107"/>
                </criteria>
                <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.17241" test_ref="oval:org.mitre.oval:tst:137700"/>
                <criteria operator="AND" comment="Jscript.dll and LDR">
                  <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.21359" test_ref="oval:org.mitre.oval:tst:137021"/>
                  <criterion comment="Check if the version of Jscript9.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:137516"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 8/ 2012 R2">
              <criteria operator="OR" comment="Win 8/ 2012">
                <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
                <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
                <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17228" test_ref="oval:org.mitre.oval:tst:137876"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21345" test_ref="oval:org.mitre.oval:tst:137107"/>
                </criteria>
                <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.17241" test_ref="oval:org.mitre.oval:tst:137700"/>
                <criteria operator="AND" comment="Jscript.dll and LDR">
                  <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.21359" test_ref="oval:org.mitre.oval:tst:137021"/>
                  <criterion comment="Check if the version of Jscript9.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:137516"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/ 2k12 R2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7/ 2k8 R2/ 8.1/ 2k12 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criteria operator="OR" comment="either file">
                <criterion comment="Check if the version of Jscript9.dll is less than 11.0.9600.17640" test_ref="oval:org.mitre.oval:tst:137882"/>
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17631" test_ref="oval:org.mitre.oval:tst:137835"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28368" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2014-6363 (MS14-080)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>VBScript 5.8</product>
          <product>VBScript 5.6</product>
          <product>VBScript 5.7</product>
        </affected>
        <reference ref_id="CVE-2014-6363" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6363" source="CVE"/>
        <description>vbscript.dll in Microsoft VBScript 5.6 through 5.8, as used with Internet Explorer 6 through 11 and other products, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "VBScript Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-12-12T10:59:59">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-12-16T00:09:44.662-05:00">DRAFT</status_change>
            <status_change date="2015-01-05T04:00:35.622-05:00">INTERIM</status_change>
            <status_change date="2015-01-26T04:00:38.727-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:115 - pattern match update for IE 7 inventory def (replaced the greedy pattern" date="2015-02-16T13:23:00.322-05:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2015-02-16T13:25:04.800-05:00">INTERIM</status_change>
            <status_change date="2015-03-09T04:01:37.560-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="VBScript 5.6 and 2K3 vulnerable version">
          <criterion comment="vbscript.dll 5.6 or later is installed" test_ref="oval:org.mitre.oval:tst:100534"/>
          <criteria operator="OR" comment=" 2K3 + vulnerable file version">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of vbscript.dll is less than 5.6.0.8853" test_ref="oval:org.mitre.oval:tst:135632"/>
          <criterion comment="Internet Explorer 6 (any patch level) is installed" test_ref="oval:org.mitre.oval:tst:2333"/>
        </criteria>
        <criteria operator="AND" comment="VBScript 5.7 and 2K3/Vista/2k8 vulnerable version">
          <criterion comment="Vbscript.dll 5.7 or later is installed" test_ref="oval:org.mitre.oval:tst:11558"/>
          <criteria operator="OR" comment="2K3/Vista/2k8 vulnerable version">
            <criteria operator="AND" comment="2k3 and vulnerable file version">
              <criteria operator="OR" comment="2K3">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of vbscript.dll is less than 5.7.6002.23528" test_ref="oval:org.mitre.oval:tst:135236"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista / 2K8">
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of vbscript.dll is less than 5.7.6002.19221" test_ref="oval:org.mitre.oval:tst:135777"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of vbscript.dll is less than 5.7.6002.23528" test_ref="oval:org.mitre.oval:tst:135236"/>
                  <criterion comment="Check if the version of vbscript.dll is greater than or equal to 5.7.6002.23000" test_ref="oval:org.mitre.oval:tst:100298"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
          <criteria operator="OR" comment="IE 6/7">
            <criterion comment="Internet Explorer 7 is installed" test_ref="oval:org.mitre.oval:tst:178"/>
            <criterion comment="Internet Explorer 6 (any patch level) is installed" test_ref="oval:org.mitre.oval:tst:2333"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="VBScript 5.8 and 2K3/Vista/2k8/Win7/2k8 R2/Win 8/Win 8.1/Win 2k12/Win 2k12 R2 vulnerable version">
          <criterion comment="Vbscript.dll 5.8 or later is installed" test_ref="oval:org.mitre.oval:tst:11329"/>
          <criteria operator="OR" comment="2K3/Vista/2K8/Win7/R2 + VBScript 5.8 + vulnerable version">
            <criteria operator="AND" comment=" /2k3 and vulnerable version">
              <criteria operator="OR" comment="/ 2K3">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of vbscript.dll is less than 5.8.6001.23642" test_ref="oval:org.mitre.oval:tst:135324"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2K8 and vulnerable file version">
              <criteria operator="OR" comment="Vista / 2K8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of vbscript.dll is less than 5.8.6001.19587" test_ref="oval:org.mitre.oval:tst:135764"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of vbscript.dll is less than 5.8.6001.23642" test_ref="oval:org.mitre.oval:tst:135324"/>
                  <criterion comment="Check if the version of Vbcript.dll is greater than or equal to 5.8.6001.23000" test_ref="oval:org.mitre.oval:tst:99962"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win7/R2 + vulnerable file version">
              <criteria operator="OR" comment="Win7/R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="vulnerable file version">
                <criterion comment="Check if the version of vbscript.dll is less than 5.8.7601.18648" test_ref="oval:org.mitre.oval:tst:134997"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of vbscript.dll is less than 5.8.7601.22856" test_ref="oval:org.mitre.oval:tst:135690"/>
                  <criterion comment="Check if the version of vbscript.dll is greater than or equal 5.8.7601.22000" test_ref="oval:org.mitre.oval:tst:113859"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
          <criterion comment="Internet Explorer 8 is installed" test_ref="oval:org.mitre.oval:tst:9082"/>
        </criteria>
        <criteria operator="AND" comment="Vbscript.dll 5.8 and vul version">
          <criterion comment="Vbscript.dll 5.8 or later is installed" test_ref="oval:org.mitre.oval:tst:11329"/>
          <criteria operator="OR" comment="2k8/Win7/2k8 R2/Win 8/Win 8.1/Win 2k12/Win 2k12 R2 vulnerable version">
            <criteria operator="AND" comment="Vista/2k8/Win7/R2 and IE 8 + vulnerable file version">
              <criteria operator="OR" comment="Vista / 2K8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of vbscript.dll is less than 5.8.7601.17104" test_ref="oval:org.mitre.oval:tst:135537"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Vbscript.dll version is greater than or equal 5.8.7601.20000" test_ref="oval:org.mitre.oval:tst:41925"/>
                  <criterion comment="Check if the version of vbscript.dll is less than 5.8.7601.20716" test_ref="oval:org.mitre.oval:tst:135655"/>
                </criteria>
              </criteria>
              <criterion comment="Internet Explorer 9 is installed" test_ref="oval:org.mitre.oval:tst:42359"/>
            </criteria>
            <criteria operator="AND" comment="Win7/R2/Win8/2k12 and IE 10 + vulnerable file version">
              <criterion comment="Check if Microsoft Internet Explorer 10 is installed" test_ref="oval:org.mitre.oval:tst:80429"/>
              <criteria operator="OR" comment="Win7/R2/Win8/2k12 + VBScript 5.8 + vulnerable version">
                <criteria operator="AND" comment="Win7/R2 and IE 10 + vulnerable file version">
                  <criteria operator="OR" comment="Win7/R2">
                    <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                    <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                    <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                  </criteria>
                  <criteria operator="OR" comment="Check for vulnerable version">
                    <criterion comment="Check if the version of vbscript.dll is less than 5.8.9200.17183" test_ref="oval:org.mitre.oval:tst:135745"/>
                    <criteria operator="AND" comment="Check for LDR">
                      <criterion comment="Check if the version of vbscript.dll is greater than or equal to 5.8.9200.21000" test_ref="oval:org.mitre.oval:tst:135738"/>
                      <criterion comment="Check if the version of vbscript.dll is less than 5.8.9200.21299" test_ref="oval:org.mitre.oval:tst:135669"/>
                    </criteria>
                  </criteria>
                </criteria>
                <criteria operator="AND" comment="Win 8 / 2012 and vulnerable file version">
                  <criteria operator="OR" comment="Win 8 / 2k12">
                    <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
                    <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
                    <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
                  </criteria>
                  <criteria operator="OR" comment="Check for vulnerable version">
                    <criterion comment="Check if the version of jscript.dll is less than 5.8.9200.17183" test_ref="oval:org.mitre.oval:tst:135549"/>
                    <criteria operator="AND" comment="Check for LDR">
                      <criterion comment="Check if the version of jscript.dll is less than 5.8.9200.21299" test_ref="oval:org.mitre.oval:tst:134918"/>
                      <criterion comment="Check if the version of jscript.dll is greater than or equal to 5.8.9200.21000" test_ref="oval:org.mitre.oval:tst:135737"/>
                    </criteria>
                  </criteria>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win7/R2/Win8.1/2k12 R2 and IE 11 + vulnerable file version">
              <criteria operator="OR" comment="Win7/R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criterion comment="Check if the version of vbscript.dll is less than 5.8.9600.17496" test_ref="oval:org.mitre.oval:tst:135651"/>
              <criterion comment="Check if Microsoft Internet Explorer 11 is installed" test_ref="oval:org.mitre.oval:tst:87142"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28358" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2014-6343 (MS14-065)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2014-6343" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6343" source="CVE"/>
        <description>Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-18T10:59:59">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-11-20T23:04:14.494-05:00">DRAFT</status_change>
            <status_change date="2014-12-08T04:01:04.111-05:00">INTERIM</status_change>
            <status_change date="2014-12-29T04:00:47.178-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:135132 - States changed in accordance with MS14-065" date="2015-02-03T13:27:00.224-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-03T13:31:11.959-05:00">INTERIM</status_change>
            <status_change date="2015-02-23T04:01:17.556-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16592" test_ref="oval:org.mitre.oval:tst:135694"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20708" test_ref="oval:org.mitre.oval:tst:135680"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17173" test_ref="oval:org.mitre.oval:tst:135132"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21291" test_ref="oval:org.mitre.oval:tst:135567"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17420" test_ref="oval:org.mitre.oval:tst:135492"/>
            </criteria>
            <criteria operator="AND" comment="Win 8.1 / 2k12 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17416" test_ref="oval:org.mitre.oval:tst:135746"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28347" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-0027 (MS15-009)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-0027" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0027" source="CVE"/>
        <description>Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-0035, CVE-2015-0039, CVE-2015-0052, and CVE-2015-0068.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-02-13T10:59:59">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-02-16T13:11:16.996-05:00">DRAFT</status_change>
            <status_change date="2015-03-09T04:01:35.895-04:00">INTERIM</status_change>
            <status_change date="2015-03-30T04:00:15.322-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <criteria operator="AND" comment="Win 7/R2">
              <criteria operator="OR" comment="Win 7/R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17229" test_ref="oval:org.mitre.oval:tst:137987"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21345" test_ref="oval:org.mitre.oval:tst:137107"/>
                </criteria>
                <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.17241" test_ref="oval:org.mitre.oval:tst:137700"/>
                <criteria operator="AND" comment="Jscript.dll and LDR">
                  <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.21359" test_ref="oval:org.mitre.oval:tst:137021"/>
                  <criterion comment="Check if the version of Jscript9.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:137516"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 8/ 2012 R2">
              <criteria operator="OR" comment="Win 8/ 2012">
                <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
                <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
                <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17228" test_ref="oval:org.mitre.oval:tst:137876"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21345" test_ref="oval:org.mitre.oval:tst:137107"/>
                </criteria>
                <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.17241" test_ref="oval:org.mitre.oval:tst:137700"/>
                <criteria operator="AND" comment="Jscript.dll and LDR">
                  <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.21359" test_ref="oval:org.mitre.oval:tst:137021"/>
                  <criterion comment="Check if the version of Jscript9.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:137516"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/ 2k12 R2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7/ 2k8 R2/ 8.1/ 2k12 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criteria operator="OR" comment="either file">
                <criterion comment="Check if the version of Jscript9.dll is less than 11.0.9600.17640" test_ref="oval:org.mitre.oval:tst:137882"/>
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17631" test_ref="oval:org.mitre.oval:tst:137835"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28339" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer cross-domain information disclosure vulnerability. - CVE-2014-6340 (MS14-065)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
          <product>Microsoft Internet Explorer 6</product>
        </affected>
        <reference ref_id="CVE-2014-6340" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6340" source="CVE"/>
        <description>Microsoft Internet Explorer 6 through 11 allows remote attackers to read content from a different (1) domain or (2) zone via a crafted web site, aka "Internet Explorer Cross-domain Information Disclosure Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-18T10:59:59">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-11-20T23:04:09.697-05:00">DRAFT</status_change>
            <status_change date="2014-12-08T04:01:03.801-05:00">INTERIM</status_change>
            <status_change date="2014-12-29T04:00:46.417-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:135132 - States changed in accordance with MS14-065" date="2015-02-03T13:27:00.224-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-03T13:31:12.081-05:00">INTERIM</status_change>
            <status_change date="2015-02-23T04:01:16.958-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23633" test_ref="oval:org.mitre.oval:tst:135078"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19575" test_ref="oval:org.mitre.oval:tst:135657"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23633" test_ref="oval:org.mitre.oval:tst:135078"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18631" test_ref="oval:org.mitre.oval:tst:135382"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22838" test_ref="oval:org.mitre.oval:tst:135196"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16592" test_ref="oval:org.mitre.oval:tst:135694"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20708" test_ref="oval:org.mitre.oval:tst:135680"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21415" test_ref="oval:org.mitre.oval:tst:135682"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista / 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19212" test_ref="oval:org.mitre.oval:tst:135209"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23517" test_ref="oval:org.mitre.oval:tst:135641"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17173" test_ref="oval:org.mitre.oval:tst:135132"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21291" test_ref="oval:org.mitre.oval:tst:135567"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17420" test_ref="oval:org.mitre.oval:tst:135492"/>
            </criteria>
            <criteria operator="AND" comment="Win 8.1 / 2k12 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17416" test_ref="oval:org.mitre.oval:tst:135746"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5458" test_ref="oval:org.mitre.oval:tst:135695"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28337" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-0017 (MS15-009)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
          <product>Microsoft Internet Explorer 6</product>
        </affected>
        <reference ref_id="CVE-2015-0017" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0017" source="CVE"/>
        <description>Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-0020, CVE-2015-0022, CVE-2015-0026, CVE-2015-0030, CVE-2015-0031, CVE-2015-0036, and CVE-2015-0041.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-02-13T10:59:59">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-02-16T13:11:59.971-05:00">DRAFT</status_change>
            <status_change date="2015-03-09T04:01:35.385-04:00">INTERIM</status_change>
            <status_change date="2015-03-30T04:00:14.788-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5508" test_ref="oval:org.mitre.oval:tst:137925"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21432" test_ref="oval:org.mitre.oval:tst:138027"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista / 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19281" test_ref="oval:org.mitre.oval:tst:138002"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23590" test_ref="oval:org.mitre.oval:tst:137924"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23644" test_ref="oval:org.mitre.oval:tst:137686"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19600" test_ref="oval:org.mitre.oval:tst:137706"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23655" test_ref="oval:org.mitre.oval:tst:137677"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18715" test_ref="oval:org.mitre.oval:tst:138039"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22921" test_ref="oval:org.mitre.oval:tst:137991"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16609" test_ref="oval:org.mitre.oval:tst:138073"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20725" test_ref="oval:org.mitre.oval:tst:137846"/>
            </criteria>
            <criterion comment="Check if the version of Jscript9.dll is less than 9.0.8112.16620" test_ref="oval:org.mitre.oval:tst:137873"/>
            <criteria operator="AND" comment="Jscript and LDR">
              <criterion comment="Check if the version of Jscript9.dll is less than 9.0.8112.20730" test_ref="oval:org.mitre.oval:tst:137974"/>
              <criterion comment="Check if the version of Jscript9.dll is greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:137868"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <criteria operator="AND" comment="Win 7/R2">
              <criteria operator="OR" comment="Win 7/R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17229" test_ref="oval:org.mitre.oval:tst:137987"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21345" test_ref="oval:org.mitre.oval:tst:137107"/>
                </criteria>
                <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.17241" test_ref="oval:org.mitre.oval:tst:137700"/>
                <criteria operator="AND" comment="Jscript.dll and LDR">
                  <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.21359" test_ref="oval:org.mitre.oval:tst:137021"/>
                  <criterion comment="Check if the version of Jscript9.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:137516"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 8/ 2012 R2">
              <criteria operator="OR" comment="Win 8/ 2012">
                <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
                <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
                <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17228" test_ref="oval:org.mitre.oval:tst:137876"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21345" test_ref="oval:org.mitre.oval:tst:137107"/>
                </criteria>
                <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.17241" test_ref="oval:org.mitre.oval:tst:137700"/>
                <criteria operator="AND" comment="Jscript.dll and LDR">
                  <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.21359" test_ref="oval:org.mitre.oval:tst:137021"/>
                  <criterion comment="Check if the version of Jscript9.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:137516"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/ 2k12 R2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7/ 2k8 R2/ 8.1/ 2k12 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criteria operator="OR" comment="either file">
                <criterion comment="Check if the version of Jscript9.dll is less than 11.0.9600.17640" test_ref="oval:org.mitre.oval:tst:137882"/>
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17631" test_ref="oval:org.mitre.oval:tst:137835"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28334" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer Clipboard Information Disclosure Vulnerability - CVE-2014-6323 (MS14-065)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
          <product>Microsoft Internet Explorer 7</product>
        </affected>
        <reference ref_id="CVE-2014-6323" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6323" source="CVE"/>
        <description>Microsoft Internet Explorer 7 through 11 allows remote attackers to obtain sensitive clipboard information via a crafted web site, aka "Internet Explorer Clipboard Information Disclosure Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-18T10:59:59">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-11-20T23:04:12.533-05:00">DRAFT</status_change>
            <status_change date="2014-12-08T04:01:03.514-05:00">INTERIM</status_change>
            <status_change date="2014-12-29T04:00:45.828-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:135132 - States changed in accordance with MS14-065" date="2015-02-03T13:27:00.224-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-03T13:31:12.242-05:00">INTERIM</status_change>
            <status_change date="2015-02-23T04:01:16.644-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 )">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23633" test_ref="oval:org.mitre.oval:tst:135078"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19575" test_ref="oval:org.mitre.oval:tst:135657"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23633" test_ref="oval:org.mitre.oval:tst:135078"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18631" test_ref="oval:org.mitre.oval:tst:135382"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22838" test_ref="oval:org.mitre.oval:tst:135196"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16592" test_ref="oval:org.mitre.oval:tst:135694"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20708" test_ref="oval:org.mitre.oval:tst:135680"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17173" test_ref="oval:org.mitre.oval:tst:135132"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21291" test_ref="oval:org.mitre.oval:tst:135567"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17420" test_ref="oval:org.mitre.oval:tst:135492"/>
            </criteria>
            <criteria operator="AND" comment="Win 8.1 / 2k12 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17416" test_ref="oval:org.mitre.oval:tst:135746"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21415" test_ref="oval:org.mitre.oval:tst:135682"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista / 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19212" test_ref="oval:org.mitre.oval:tst:135209"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23517" test_ref="oval:org.mitre.oval:tst:135641"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28330" version="3" class="vulnerability">
      <metadata>
        <title>Microsoft user profile service elevation of privilege vulnerability - CVE-2015-0004 (MS15-003)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-0004" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0004"/>
        <description>The User Profile Service (aka ProfSvc) in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges by conducting a junction attack to load another user's UsrClass.dat registry hive, aka MSRC ID 20674 or "Microsoft User Profile Service Elevation of Privilege Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-01-16T10:55:27">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-01-16T19:14:17.736-05:00">DRAFT</status_change>
            <status_change date="2015-02-02T04:00:19.364-05:00">INTERIM</status_change>
            <status_change date="2015-02-23T04:01:16.284-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Server 2003 and vulnerable file version">
          <criteria operator="OR" comment="Server 2003 (x86/x64/ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of userenv.dll is less than 5.2.3790.5491" test_ref="oval:org.mitre.oval:tst:136728"/>
        </criteria>
        <criteria operator="AND" comment="Vista / 2k8 and vulnerable version">
          <criteria operator="OR" comment="Vista (x86/x64) / 2k8 (x86/x64/ia64)">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of Profsvc.dll is less than 6.0.6002.19250" test_ref="oval:org.mitre.oval:tst:137272"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Profsvc.dll is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:137569"/>
              <criterion comment="Check if the version of Profsvc.dll is less than or equal to 6.0.6002.23557" test_ref="oval:org.mitre.oval:tst:137532"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / R2 and vulnerable files version">
          <criteria operator="OR" comment="Win7 (x86/x64) / 2k8R2 (x86/x64/ia64)">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of Profsvc.dll is less than 6.1.7601.18706" test_ref="oval:org.mitre.oval:tst:137372"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Profsvc.dll is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:137095"/>
              <criterion comment="Check if the version of Profsvc.dll is less than 6.1.7601.22913" test_ref="oval:org.mitre.oval:tst:137455"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8 / 2k12 and vulnerable files version">
          <criteria operator="OR" comment="Win8 (x86/x64) / 2k12 (x64)">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of Profsvc.dll is less than 6.2.9200.17219" test_ref="oval:org.mitre.oval:tst:137592"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Profsvc.dll is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:137468"/>
              <criterion comment="Check if the version of Profsvc.dll is less than 6.2.9200.21317" test_ref="oval:org.mitre.oval:tst:137561"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1/ 2k12 R2 and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1/ 2k12 R2 and vulnerable file version">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of Profsvc.dll is less than 6.3.9600.17552" test_ref="oval:org.mitre.oval:tst:137408"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28328" version="3" class="vulnerability">
      <metadata>
        <title>OWA XSS vulnerability (CVE-2014-6326) - MS14-075</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Exchange Server 2013</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-6326" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6326"/>
        <description>Cross-site scripting (XSS) vulnerability in Microsoft Exchange Server 2013 SP1 and Cumulative Update 6 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka "OWA XSS Vulnerability," a different vulnerability than CVE-2014-6325.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-12-12T15:06:06">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-12-15T23:58:18.138-05:00">DRAFT</status_change>
            <status_change date="2015-01-05T04:00:32.118-05:00">INTERIM</status_change>
            <status_change date="2015-01-26T04:00:35.683-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Exchange Server 2013 and vulnerable file version">
          <extend_definition comment="Microsoft Exchange Server 2013 is installed" definition_ref="oval:org.mitre.oval:def:18626"/>
          <criterion comment="Check if the version of ExSetup.exe is less than 15.00.0847.035" test_ref="oval:org.mitre.oval:tst:135793"/>
        </criteria>
        <criteria operator="AND" comment="Exchange 2013 CU 6 and vulnerable file version">
          <criterion comment="Check if the version of ExSetup.exe is less than 15.00.0995.034" test_ref="oval:org.mitre.oval:tst:135701"/>
          <extend_definition comment="Microsoft Exchange Server 2013 CU 6 is installed" definition_ref="oval:org.mitre.oval:def:28213"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28297" version="3" class="vulnerability">
      <metadata>
        <title>NLA Security Feature Bypass Vulnerability - CVE-2015-0006 (MS15-005)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-0006" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0006"/>
        <description>The Network Location Awareness (NLA) service in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 does not perform mutual authentication to determine a domain connection, which allows remote attackers to trigger an unintended permissive configuration by spoofing DNS and LDAP responses on a local network, aka "NLA Security Feature Bypass Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-01-16T11:36:06">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-01-16T19:21:51.658-05:00">DRAFT</status_change>
            <status_change date="2015-02-02T04:00:17.594-05:00">INTERIM</status_change>
            <status_change date="2015-02-23T04:01:14.578-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
        <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
        <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
        <criteria operator="AND" comment="Vista / 2k8 and vulnerable version">
          <criteria operator="OR" comment="Vista (x86/x64) / 2k8 (x86/x64/ia64)">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of Nlasvc.dll is less than 6.0.6002.19250" test_ref="oval:org.mitre.oval:tst:137124"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Nlasvc.dll is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:137327"/>
              <criterion comment="Check if the version of Nlasvc.dll is less than or equal to 6.0.6002.23557" test_ref="oval:org.mitre.oval:tst:136962"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / R2 and vulnerable files version">
          <criteria operator="OR" comment="Win7 (x86/x64) / 2k8R2 (x86/x64/ia64)">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of Nlasvc.dll is less than 6.1.7601.18685" test_ref="oval:org.mitre.oval:tst:137657"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Nlasvc.dll is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:137339"/>
              <criterion comment="Check if the version of Nlasvc.dll is less than 6.1.7601.22893" test_ref="oval:org.mitre.oval:tst:137638"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8 / 2k12 and vulnerable files version">
          <criteria operator="OR" comment="Win8 (x86/x64) / 2k12 (x64)">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of Nlasvc.dll is less than 6.2.9200.17199" test_ref="oval:org.mitre.oval:tst:137618"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Nlasvc.dll is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:137398"/>
              <criterion comment="Check if the version of Nlasvc.dll is less than 6.2.9200.21316" test_ref="oval:org.mitre.oval:tst:137617"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1/ 2k12 R2 and vulnerable file version">
          <criteria operator="OR" comment="Windows 8.1/2k12">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of Nlasvc.dll is less than 6.3.9600.17550" test_ref="oval:org.mitre.oval:tst:136722"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28291" version="3" class="vulnerability">
      <metadata>
        <title>OWA XSS vulnerability (CVE-2014-6325) - MS14-075</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Exchange Server 2013</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-6325" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6325"/>
        <description>Cross-site scripting (XSS) vulnerability in Microsoft Exchange Server 2013 SP1 and Cumulative Update 6 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka "OWA XSS Vulnerability," a different vulnerability than CVE-2014-6326.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-12-12T15:06:06">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-12-15T23:58:19.017-05:00">DRAFT</status_change>
            <status_change date="2015-01-05T04:00:28.586-05:00">INTERIM</status_change>
            <status_change date="2015-01-26T04:00:32.459-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Exchange Server 2013 and vulnerable file version">
          <extend_definition comment="Microsoft Exchange Server 2013 is installed" definition_ref="oval:org.mitre.oval:def:18626"/>
          <criterion comment="Check if the version of ExSetup.exe is less than 15.00.0847.035" test_ref="oval:org.mitre.oval:tst:135793"/>
        </criteria>
        <criteria operator="AND" comment="Exchange 2013 CU 6 and vulnerable file version">
          <criterion comment="Check if the version of ExSetup.exe is less than 15.00.0995.034" test_ref="oval:org.mitre.oval:tst:135701"/>
          <extend_definition comment="Microsoft Exchange Server 2013 CU 6 is installed" definition_ref="oval:org.mitre.oval:def:28213"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28213" version="3" class="inventory">
      <metadata>
        <title>Microsoft Exchange Server 2013 CU 6 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Exchange Server 2013</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:exchange_server:2013:cu6"/>
        <description>Microsoft Exchange Server 2013 CU 6 is installed. Microsoft Exchange Server is calendaring software, a mail server and contact manager developed by Microsoft.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-12-12T14:23:36">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-12-15T23:58:16.589-05:00">DRAFT</status_change>
            <status_change date="2015-01-05T04:00:24.485-05:00">INTERIM</status_change>
            <status_change date="2015-01-26T04:00:28.280-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Microsoft Exchange Server 2013 is installed" definition_ref="oval:org.mitre.oval:def:18626"/>
        <criterion comment="Microsoft Exchange Server Cumulative Update 6 is installed" test_ref="oval:org.mitre.oval:tst:135802"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:18626" version="3" class="inventory">
      <metadata>
        <title>Microsoft Exchange Server 2013 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <product>Microsoft Exchange Server 2013</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:exchange_server:2013"/>
        <description>Microsoft Exchange Server 2013 is installed</description>
        <oval_repository>
          <dates>
            <submitted date="2013-09-03T10:20:20">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-09-04T14:49:15.323-04:00">DRAFT</status_change>
            <status_change date="2013-09-23T04:05:38.765-04:00">INTERIM</status_change>
            <status_change date="2013-10-14T04:00:17.937-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="Check if Exchange Server 2013 is installed" test_ref="oval:org.mitre.oval:tst:86283"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28290" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer cross-domain information disclosure vulnerability - CVE-2014-6346 (MS14-065)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2014-6346" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6346" source="CVE"/>
        <description>Microsoft Internet Explorer 8 through 11 allows remote attackers to read content from a different (1) domain or (2) zone via a crafted web site, aka "Internet Explorer Cross-domain Information Disclosure Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-18T10:59:59">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-11-20T23:03:58.998-05:00">DRAFT</status_change>
            <status_change date="2014-12-08T04:01:02.685-05:00">INTERIM</status_change>
            <status_change date="2014-12-29T04:00:44.081-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:135132 - States changed in accordance with MS14-065" date="2015-02-03T13:27:00.224-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-03T13:31:12.410-05:00">INTERIM</status_change>
            <status_change date="2015-02-23T04:01:14.181-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23633" test_ref="oval:org.mitre.oval:tst:135078"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19575" test_ref="oval:org.mitre.oval:tst:135657"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23633" test_ref="oval:org.mitre.oval:tst:135078"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18631" test_ref="oval:org.mitre.oval:tst:135382"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22838" test_ref="oval:org.mitre.oval:tst:135196"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16592" test_ref="oval:org.mitre.oval:tst:135694"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20708" test_ref="oval:org.mitre.oval:tst:135680"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17173" test_ref="oval:org.mitre.oval:tst:135132"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21291" test_ref="oval:org.mitre.oval:tst:135567"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17420" test_ref="oval:org.mitre.oval:tst:135492"/>
            </criteria>
            <criteria operator="AND" comment="Win 8.1 / 2k12 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17416" test_ref="oval:org.mitre.oval:tst:135746"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28283" version="3" class="vulnerability">
      <metadata>
        <title>Windows audio service vulnerability - CVE-2014-6322 (MS14-071)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-6322" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6322"/>
        <description>The Windows Audio service in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to gain privileges via a crafted web site, as demonstrated by execution of web script in Internet Explorer, aka "Windows Audio Service Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-14T10:57:41">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-11-17T17:19:16.188-05:00">DRAFT</status_change>
            <status_change date="2014-12-08T04:01:02.020-05:00">INTERIM</status_change>
            <status_change date="2014-12-29T04:00:42.592-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
          <criteria operator="OR" comment="Vista / 2k8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of audiosrv.dll is less than 6.0.6002.19201" test_ref="oval:org.mitre.oval:tst:135449"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of audiosrv.dll is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:135265"/>
              <criterion comment="Check if the version of audiosrv.dll is less than 6.0.6002.23506" test_ref="oval:org.mitre.oval:tst:135327"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / 2k8 R2 and vulnerable file version">
          <criteria operator="OR" comment="Win 7 / 2k8 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of audiosrv.dll is less than 6.1.7601.18619" test_ref="oval:org.mitre.oval:tst:135244"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of audiosrv.dll is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:135217"/>
              <criterion comment="Check if the version of audiosrv.dll is less than 6.1.7601.22826" test_ref="oval:org.mitre.oval:tst:135372"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8 / 2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of audiosrv.dll is less than 6.2.9200.17134" test_ref="oval:org.mitre.oval:tst:134576"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of audiosrv.dll is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:135321"/>
              <criterion comment="Check if the version of audiosrv.dll is less than 6.2.9200.21251" test_ref="oval:org.mitre.oval:tst:135173"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1 / 2k12 R2 and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of audiosrv.dll is less than 6.3.9600.17393" test_ref="oval:org.mitre.oval:tst:135290"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28272" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-0068 (MS15-009)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-0068" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0068" source="CVE"/>
        <description>Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-0027, CVE-2015-0035, CVE-2015-0039, and CVE-2015-0052.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-02-13T10:59:59">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-02-16T13:12:11.199-05:00">DRAFT</status_change>
            <status_change date="2015-03-09T04:01:32.804-04:00">INTERIM</status_change>
            <status_change date="2015-03-30T04:00:13.785-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <criteria operator="AND" comment="Win 7/R2">
              <criteria operator="OR" comment="Win 7/R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17229" test_ref="oval:org.mitre.oval:tst:137987"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21345" test_ref="oval:org.mitre.oval:tst:137107"/>
                </criteria>
                <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.17241" test_ref="oval:org.mitre.oval:tst:137700"/>
                <criteria operator="AND" comment="Jscript.dll and LDR">
                  <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.21359" test_ref="oval:org.mitre.oval:tst:137021"/>
                  <criterion comment="Check if the version of Jscript9.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:137516"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 8/ 2012 R2">
              <criteria operator="OR" comment="Win 8/ 2012">
                <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
                <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
                <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17228" test_ref="oval:org.mitre.oval:tst:137876"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21345" test_ref="oval:org.mitre.oval:tst:137107"/>
                </criteria>
                <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.17241" test_ref="oval:org.mitre.oval:tst:137700"/>
                <criteria operator="AND" comment="Jscript.dll and LDR">
                  <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.21359" test_ref="oval:org.mitre.oval:tst:137021"/>
                  <criterion comment="Check if the version of Jscript9.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:137516"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/ 2k12 R2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7/ 2k8 R2/ 8.1/ 2k12 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criteria operator="OR" comment="either file">
                <criterion comment="Check if the version of Jscript9.dll is less than 11.0.9600.17640" test_ref="oval:org.mitre.oval:tst:137882"/>
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17631" test_ref="oval:org.mitre.oval:tst:137835"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28270" version="3" class="vulnerability">
      <metadata>
        <title>Remote Desktop Protocol (RDP) failure to audit vulnerability - CVE-2014-6318 (MS14-074)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-6318" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6318"/>
        <description>The audit logon feature in Remote Desktop Protocol (RDP) in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 does not properly log unauthorized login attempts supplying valid credentials, which makes it easier for remote attackers to bypass intended access restrictions via a series of attempts, aka "Remote Desktop Protocol (RDP) Failure to Audit Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-14T12:20:29">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-11-17T17:34:39.323-05:00">DRAFT</status_change>
            <status_change date="2014-12-08T04:01:01.741-05:00">INTERIM</status_change>
            <status_change date="2014-12-29T04:00:41.881-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vista/2k8 and vulnerable version of file">
          <criteria operator="OR" comment="Vista/2k8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of lsasrv.dll is less than 6.0.6002.19214" test_ref="oval:org.mitre.oval:tst:135246"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of lsasrv.dll is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:135464"/>
              <criterion comment="Check if the version of lsasrv.dll is less than 6.0.6002.23521" test_ref="oval:org.mitre.oval:tst:135454"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / 2k8 R2 and vulnerable file version">
          <criteria operator="OR" comment="Win 7/ 2k8 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of lsasrv.dll is less than 6.1.7601.18637" test_ref="oval:org.mitre.oval:tst:135351"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of lsasrv.dll is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:135369"/>
              <criterion comment="Check if the version of lsasrv.dll is less than 6.1.7601.22843" test_ref="oval:org.mitre.oval:tst:135429"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8 / Server 2012 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of lsasrv.dll is less than 6.2.9200.17150" test_ref="oval:org.mitre.oval:tst:135414"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of lsasrv.dll is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:135331"/>
              <criterion comment="Check if the version of lsasrv.dll is less than 6.2.9200.21269" test_ref="oval:org.mitre.oval:tst:134506"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="8.1/2k12 R2 and vulnerable file version">
          <criteria operator="OR" comment="8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of lsasrv.dll is less than 6.3.9600.17396" test_ref="oval:org.mitre.oval:tst:134479"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28266" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer elevation of privilege vulnerability - CVE-2014-6349 (MS14-065)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2014-6349" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6349" source="CVE"/>
        <description>Microsoft Internet Explorer 10 and 11 allows remote attackers to gain privileges via a crafted web site, aka "Internet Explorer Elevation of Privilege Vulnerability," a different vulnerability than CVE-2014-6350.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-18T10:59:59">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-11-20T23:04:06.898-05:00">DRAFT</status_change>
            <status_change date="2014-12-08T04:01:01.352-05:00">INTERIM</status_change>
            <status_change date="2014-12-29T04:00:41.011-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:135132 - States changed in accordance with MS14-065" date="2015-02-03T13:27:00.224-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-03T13:31:12.548-05:00">INTERIM</status_change>
            <status_change date="2015-02-23T04:01:13.994-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17173" test_ref="oval:org.mitre.oval:tst:135132"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21291" test_ref="oval:org.mitre.oval:tst:135567"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17420" test_ref="oval:org.mitre.oval:tst:135492"/>
            </criteria>
            <criteria operator="AND" comment="Win 8.1 / 2k12 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17416" test_ref="oval:org.mitre.oval:tst:135746"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28257" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer ASLR bypass vulnerability - CVE-2015-0071 (MS15-009)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-0071" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0071" source="CVE"/>
        <description>Microsoft Internet Explorer 9 through 11 allows remote attackers to bypass the ASLR protection mechanism via a crafted web site, aka "Internet Explorer ASLR Bypass Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-02-13T10:59:59">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-02-16T13:11:53.643-05:00">DRAFT</status_change>
            <status_change date="2015-03-09T04:01:32.057-04:00">INTERIM</status_change>
            <status_change date="2015-03-30T04:00:13.356-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16609" test_ref="oval:org.mitre.oval:tst:138073"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20725" test_ref="oval:org.mitre.oval:tst:137846"/>
            </criteria>
            <criterion comment="Check if the version of Jscript9.dll is less than 9.0.8112.16620" test_ref="oval:org.mitre.oval:tst:137873"/>
            <criteria operator="AND" comment="Jscript and LDR">
              <criterion comment="Check if the version of Jscript9.dll is less than 9.0.8112.20730" test_ref="oval:org.mitre.oval:tst:137974"/>
              <criterion comment="Check if the version of Jscript9.dll is greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:137868"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <criteria operator="AND" comment="Win 7/R2">
              <criteria operator="OR" comment="Win 7/R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17229" test_ref="oval:org.mitre.oval:tst:137987"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21345" test_ref="oval:org.mitre.oval:tst:137107"/>
                </criteria>
                <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.17241" test_ref="oval:org.mitre.oval:tst:137700"/>
                <criteria operator="AND" comment="Jscript.dll and LDR">
                  <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.21359" test_ref="oval:org.mitre.oval:tst:137021"/>
                  <criterion comment="Check if the version of Jscript9.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:137516"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 8/ 2012 R2">
              <criteria operator="OR" comment="Win 8/ 2012">
                <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
                <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
                <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17228" test_ref="oval:org.mitre.oval:tst:137876"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21345" test_ref="oval:org.mitre.oval:tst:137107"/>
                </criteria>
                <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.17241" test_ref="oval:org.mitre.oval:tst:137700"/>
                <criteria operator="AND" comment="Jscript.dll and LDR">
                  <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.21359" test_ref="oval:org.mitre.oval:tst:137021"/>
                  <criterion comment="Check if the version of Jscript9.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:137516"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/ 2k12 R2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7/ 2k8 R2/ 8.1/ 2k12 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criteria operator="OR" comment="either file">
                <criterion comment="Check if the version of Jscript9.dll is less than 11.0.9600.17640" test_ref="oval:org.mitre.oval:tst:137882"/>
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17631" test_ref="oval:org.mitre.oval:tst:137835"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28205" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2014-6353 (MS14-065)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
        </affected>
        <reference ref_id="CVE-2014-6353" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6353" source="CVE"/>
        <description>Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-18T10:59:59">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-11-20T23:04:18.028-05:00">DRAFT</status_change>
            <status_change date="2014-12-08T04:00:58.623-05:00">INTERIM</status_change>
            <status_change date="2014-12-29T04:00:35.777-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:135132 - States changed in accordance with MS14-065" date="2015-02-03T13:27:00.224-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-03T13:31:12.886-05:00">INTERIM</status_change>
            <status_change date="2015-02-23T04:01:12.087-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23633" test_ref="oval:org.mitre.oval:tst:135078"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19575" test_ref="oval:org.mitre.oval:tst:135657"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23633" test_ref="oval:org.mitre.oval:tst:135078"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18631" test_ref="oval:org.mitre.oval:tst:135382"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22838" test_ref="oval:org.mitre.oval:tst:135196"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16592" test_ref="oval:org.mitre.oval:tst:135694"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20708" test_ref="oval:org.mitre.oval:tst:135680"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21415" test_ref="oval:org.mitre.oval:tst:135682"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista / 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19212" test_ref="oval:org.mitre.oval:tst:135209"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23517" test_ref="oval:org.mitre.oval:tst:135641"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17173" test_ref="oval:org.mitre.oval:tst:135132"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21291" test_ref="oval:org.mitre.oval:tst:135567"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5458" test_ref="oval:org.mitre.oval:tst:135695"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28204" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer cross-domain information disclosure vulnerability - CVE-2014-6345 (MS14-065)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
        </affected>
        <reference ref_id="CVE-2014-6345" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6345" source="CVE"/>
        <description>Microsoft Internet Explorer 9 and 10 allows remote attackers to read content from a different (1) domain or (2) zone via a crafted web site, aka "Internet Explorer Cross-domain Information Disclosure Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-18T10:59:59">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-11-20T23:04:26.269-05:00">DRAFT</status_change>
            <status_change date="2014-12-08T04:00:58.457-05:00">INTERIM</status_change>
            <status_change date="2014-12-29T04:00:35.385-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:135132 - States changed in accordance with MS14-065" date="2015-02-03T13:27:00.224-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-03T13:31:12.629-05:00">INTERIM</status_change>
            <status_change date="2015-02-23T04:01:11.836-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17173" test_ref="oval:org.mitre.oval:tst:135132"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21291" test_ref="oval:org.mitre.oval:tst:135567"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16592" test_ref="oval:org.mitre.oval:tst:135694"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20708" test_ref="oval:org.mitre.oval:tst:135680"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28202" version="5" class="vulnerability">
      <metadata>
        <title>CNG security feature bypass vulnerability - CVE-2015-0010 (MS15-010)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-0010" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0010"/>
        <description>The CryptProtectMemory function in cng.sys (aka the Cryptography Next Generation driver) in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1, when the CRYPTPROTECTMEMORY_SAME_LOGON option is used, does not check an impersonation token's level, which allows local users to bypass intended decryption restrictions by leveraging a service that (1) has a named-pipe planting vulnerability or (2) uses world-readable shared memory for encrypted data, aka "CNG Security Feature Bypass Vulnerability" or MSRC ID 20707.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-02-13T09:23:57">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-02-16T13:13:44.543-05:00">DRAFT</status_change>
            <status_change date="2015-03-09T04:01:30.073-04:00">INTERIM</status_change>
            <status_change date="2015-03-30T04:00:12.910-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:43353 - MS Bulletins - May 2015" date="2015-05-28T14:09:00.599-04:00">
              <contributor organization="SecPod Technologies">Kumarswamy S</contributor>
            </modified>
            <status_change date="2015-05-28T14:13:09.132-04:00">INTERIM</status_change>
            <status_change date="2015-06-15T04:00:13.933-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Windows Server 2k3 and vulnerable file version">
          <criteria operator="OR" comment="Either OS">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criteria operator="OR" comment="either version">
            <criterion comment="Check if the version of win32k.sys is less than 5.2.3790.5513" test_ref="oval:org.mitre.oval:tst:137893"/>
            <criterion comment="Check if the version of Schannnel.dll is less than 5.2.3790.5516" test_ref="oval:org.mitre.oval:tst:137932"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Vista / 2k8 + vulnerable file version">
          <criteria operator="OR" comment="Vista / 2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.0.6002.19279" test_ref="oval:org.mitre.oval:tst:137920"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:81723"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.0.6002.23588" test_ref="oval:org.mitre.oval:tst:138008"/>
            </criteria>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of Ksecdd.sys is less than 6.0.6002.23592" test_ref="oval:org.mitre.oval:tst:137948"/>
              <criterion comment="Check if the version of Ksecdd.sys is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:137239"/>
            </criteria>
            <criterion comment="Check if the version of Ksecdd.sys is less than 6.0.6002.19282" test_ref="oval:org.mitre.oval:tst:138056"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / R2 + vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.18713" test_ref="oval:org.mitre.oval:tst:137986"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:81763"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.22919" test_ref="oval:org.mitre.oval:tst:137933"/>
            </criteria>
            <criterion comment="Check if the version of the Cng.sys is less than 6.1.7601.18717" test_ref="oval:org.mitre.oval:tst:138087"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of the Cng.sys is less than 6.1.7601.22923" test_ref="oval:org.mitre.oval:tst:138072"/>
              <criterion comment="Check if the version of the Cng.sys is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:137664"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8/2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.17226" test_ref="oval:org.mitre.oval:tst:138100"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:115678"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.21343" test_ref="oval:org.mitre.oval:tst:137841"/>
            </criteria>
            <criterion comment="Check if the version of the Cng.sys is less than 6.2.9200.17230" test_ref="oval:org.mitre.oval:tst:137968"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of the Cng.sys is less than 6.2.9200.21347" test_ref="oval:org.mitre.oval:tst:137865"/>
              <criterion comment="Check if the version of the Cng.sys is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:137956"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1 / 2K12 R2and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of win32k.sys is less than 6.3.9600.17630" test_ref="oval:org.mitre.oval:tst:137568"/>
          <criterion comment="Check if the version of the Cng.sys is less than 6.3.9600.17633" test_ref="oval:org.mitre.oval:tst:137745"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28201" version="3" class="vulnerability">
      <metadata>
        <title>Microsoft Windows Kernel Brush Object use after free vulnerability - CVE-2015-1726 (MS15-061)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-1726" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1726"/>
        <description>Use-after-free vulnerability in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges via a crafted application, aka "Microsoft Windows Kernel Brush Object Use After Free Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-16T10:41:46">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-06-18T10:24:19.445-04:00">DRAFT</status_change>
            <status_change date="2015-07-06T04:00:08.028-04:00">INTERIM</status_change>
            <status_change date="2015-07-27T04:00:05.921-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Windows Server 2k3 and vulnerable file version">
          <criteria operator="OR" comment="Either OS">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of win32k.sys is less than 5.2.3790.5640" test_ref="oval:org.mitre.oval:tst:138918"/>
        </criteria>
        <criteria operator="AND" comment="Vista / 2k8 + vulnerable file version">
          <criteria operator="OR" comment="Vista / 2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.0.6002.19399" test_ref="oval:org.mitre.oval:tst:138917"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:81723"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.0.6002.23706" test_ref="oval:org.mitre.oval:tst:139029"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / R2 + vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.18869" test_ref="oval:org.mitre.oval:tst:138921"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:81763"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.23072" test_ref="oval:org.mitre.oval:tst:138932"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8/2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.17385" test_ref="oval:org.mitre.oval:tst:138372"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:115678"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.21496" test_ref="oval:org.mitre.oval:tst:138968"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1 / 2K12 R2and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of win32k.sys is less than 6.3.9600.17837" test_ref="oval:org.mitre.oval:tst:139008"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28193" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer elevation of privilege vulnerability - CVE-2015-0054 (MS15-009)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-0054" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0054" source="CVE"/>
        <description>Microsoft Internet Explorer 7 through 11 allows remote attackers to gain privileges via a crafted web site, aka "Internet Explorer Elevation of Privilege Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-02-13T10:59:59">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-02-16T13:11:41.896-05:00">DRAFT</status_change>
            <status_change date="2015-03-09T04:01:29.689-04:00">INTERIM</status_change>
            <status_change date="2015-03-30T04:00:12.322-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21432" test_ref="oval:org.mitre.oval:tst:138027"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista / 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19281" test_ref="oval:org.mitre.oval:tst:138002"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23590" test_ref="oval:org.mitre.oval:tst:137924"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23644" test_ref="oval:org.mitre.oval:tst:137686"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19600" test_ref="oval:org.mitre.oval:tst:137706"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23655" test_ref="oval:org.mitre.oval:tst:137677"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18715" test_ref="oval:org.mitre.oval:tst:138039"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22921" test_ref="oval:org.mitre.oval:tst:137991"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16609" test_ref="oval:org.mitre.oval:tst:138073"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20725" test_ref="oval:org.mitre.oval:tst:137846"/>
            </criteria>
            <criterion comment="Check if the version of Jscript9.dll is less than 9.0.8112.16620" test_ref="oval:org.mitre.oval:tst:137873"/>
            <criteria operator="AND" comment="Jscript and LDR">
              <criterion comment="Check if the version of Jscript9.dll is less than 9.0.8112.20730" test_ref="oval:org.mitre.oval:tst:137974"/>
              <criterion comment="Check if the version of Jscript9.dll is greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:137868"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <criteria operator="AND" comment="Win 7/R2">
              <criteria operator="OR" comment="Win 7/R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17229" test_ref="oval:org.mitre.oval:tst:137987"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21345" test_ref="oval:org.mitre.oval:tst:137107"/>
                </criteria>
                <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.17241" test_ref="oval:org.mitre.oval:tst:137700"/>
                <criteria operator="AND" comment="Jscript.dll and LDR">
                  <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.21359" test_ref="oval:org.mitre.oval:tst:137021"/>
                  <criterion comment="Check if the version of Jscript9.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:137516"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 8/ 2012 R2">
              <criteria operator="OR" comment="Win 8/ 2012">
                <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
                <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
                <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17228" test_ref="oval:org.mitre.oval:tst:137876"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21345" test_ref="oval:org.mitre.oval:tst:137107"/>
                </criteria>
                <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.17241" test_ref="oval:org.mitre.oval:tst:137700"/>
                <criteria operator="AND" comment="Jscript.dll and LDR">
                  <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.21359" test_ref="oval:org.mitre.oval:tst:137021"/>
                  <criterion comment="Check if the version of Jscript9.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:137516"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/ 2k12 R2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7/ 2k8 R2/ 8.1/ 2k12 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criteria operator="OR" comment="either file">
                <criterion comment="Check if the version of Jscript9.dll is less than 11.0.9600.17640" test_ref="oval:org.mitre.oval:tst:137882"/>
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17631" test_ref="oval:org.mitre.oval:tst:137835"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28191" version="3" class="vulnerability">
      <metadata>
        <title>Kerberos checksum vulnerability - CVE-2014-6324 (MS14-068)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Vista</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-6324" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6324"/>
        <description>The Kerberos Key Distribution Center (KDC) in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 allows remote authenticated domain users to obtain domain administrator privileges via a forged signature in a ticket, as exploited in the wild in November 2014, aka "Kerberos Checksum Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-20T09:09:33">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-11-20T23:26:00.888-05:00">DRAFT</status_change>
            <status_change date="2014-12-08T04:00:58.137-05:00">INTERIM</status_change>
            <status_change date="2014-12-29T04:00:34.473-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Server 2003 and vulnerable file version">
          <criteria operator="OR" comment="Server 2003 (x86/x64/ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of kerberos.dll is less than 5.2.3790.5467" test_ref="oval:org.mitre.oval:tst:135606"/>
        </criteria>
        <criteria operator="AND" comment="Vista/2k8(x86/x64/ia64) and vulnerable file version">
          <criteria operator="OR" comment="Vista/2k8(x86/x64/ia64)">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of Kerberos.dll is less than 6.0.6002.19220" test_ref="oval:org.mitre.oval:tst:134884"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of kerberos.dll is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:135821"/>
              <criterion comment="Check if the version of kerberos.dll is less than 6.0.6002.23527" test_ref="oval:org.mitre.oval:tst:135571"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / R2 (x86/x64/ia64) and vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of Kerberos.dll is less than 6.1.7601.18658" test_ref="oval:org.mitre.oval:tst:135724"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of kerberos.dll is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:135603"/>
              <criterion comment="Check if the version of kerberos.dll is less than 6.1.7601.22865" test_ref="oval:org.mitre.oval:tst:135774"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8/ Server 2012 (x86/x64/ia64) and vulnerable file version">
          <criteria operator="OR" comment="Win 8/ Server 2012 (x86/x64/ia64)">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of kerberos.dll is less than 6.2.9200.17172" test_ref="oval:org.mitre.oval:tst:135850"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of kerberos.dll is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:135794"/>
              <criterion comment="Check if the version of kerberos.dll is less than 6.2.9200.21289" test_ref="oval:org.mitre.oval:tst:135536"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1/2k12 R2 and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of kerberos.dll is less than 6.3.9600.17423" test_ref="oval:org.mitre.oval:tst:135721"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28177" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2014-6341 (MS14-065)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
          <product>Microsoft Internet Explorer 6</product>
        </affected>
        <reference ref_id="CVE-2014-6341" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6341" source="CVE"/>
        <description>Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-4143.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-18T10:59:59">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-11-20T23:04:23.663-05:00">DRAFT</status_change>
            <status_change date="2014-12-08T04:00:57.649-05:00">INTERIM</status_change>
            <status_change date="2014-12-29T04:00:33.392-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:28177 - States changed in accordance with MS14-065" date="2015-02-03T13:27:00.224-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-03T13:31:10.277-05:00">INTERIM</status_change>
            <status_change date="2015-02-23T04:01:11.105-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23633" test_ref="oval:org.mitre.oval:tst:135078"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19575" test_ref="oval:org.mitre.oval:tst:135657"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23633" test_ref="oval:org.mitre.oval:tst:135078"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18631" test_ref="oval:org.mitre.oval:tst:135382"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22838" test_ref="oval:org.mitre.oval:tst:135196"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16592" test_ref="oval:org.mitre.oval:tst:135694"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20708" test_ref="oval:org.mitre.oval:tst:135680"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21415" test_ref="oval:org.mitre.oval:tst:135682"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista / 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19212" test_ref="oval:org.mitre.oval:tst:135209"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23517" test_ref="oval:org.mitre.oval:tst:135641"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17173" test_ref="oval:org.mitre.oval:tst:135132"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21291" test_ref="oval:org.mitre.oval:tst:135567"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17420" test_ref="oval:org.mitre.oval:tst:135492"/>
            </criteria>
            <criteria operator="AND" comment="Win 8.1 / 2k12 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17416" test_ref="oval:org.mitre.oval:tst:135746"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5458" test_ref="oval:org.mitre.oval:tst:135695"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28172" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer XSS filter bypass vulnerability - CVE-2014-6328 (MS14-080)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2014-6328" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6328" source="CVE"/>
        <description>Microsoft Internet Explorer 8 through 11 allows remote attackers to bypass the XSS filter via a crafted attribute of an element in an HTML document, aka "Internet Explorer XSS Filter Bypass Vulnerability," a different vulnerability than CVE-2014-6365.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-12-12T10:59:59">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-12-16T00:09:48.054-05:00">DRAFT</status_change>
            <status_change date="2015-01-05T04:00:23.134-05:00">INTERIM</status_change>
            <status_change date="2015-01-26T04:00:26.718-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23642" test_ref="oval:org.mitre.oval:tst:135810"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19587" test_ref="oval:org.mitre.oval:tst:135653"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23642" test_ref="oval:org.mitre.oval:tst:135810"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18667" test_ref="oval:org.mitre.oval:tst:135861"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22874" test_ref="oval:org.mitre.oval:tst:134963"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16599" test_ref="oval:org.mitre.oval:tst:135591"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20715" test_ref="oval:org.mitre.oval:tst:135879"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17183" test_ref="oval:org.mitre.oval:tst:135488"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21299" test_ref="oval:org.mitre.oval:tst:135770"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17496" test_ref="oval:org.mitre.oval:tst:135858"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28167" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-1711 (MS15-043)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-1711" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1711" source="CVE"/>
        <description>Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-1658, CVE-2015-1706, CVE-2015-1717, and CVE-2015-1718.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-05-20T08:43:05">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-05-28T14:16:11.406-04:00">DRAFT</status_change>
            <status_change date="2015-06-15T04:00:13.660-04:00">INTERIM</status_change>
            <status_change date="2015-07-06T04:00:07.792-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
        <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
          <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
          <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
          <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
          <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
          <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
        </criteria>
        <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17801" test_ref="oval:org.mitre.oval:tst:138184"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28162" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-1706 (MS15-043)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-1706" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1706" source="CVE"/>
        <description>Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-1658, CVE-2015-1711, CVE-2015-1717, and CVE-2015-1718.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-05-20T08:43:05">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-05-28T14:15:55.138-04:00">DRAFT</status_change>
            <status_change date="2015-06-15T04:00:13.347-04:00">INTERIM</status_change>
            <status_change date="2015-07-06T04:00:07.391-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
        <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
          <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
          <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
          <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
          <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
          <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
        </criteria>
        <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17801" test_ref="oval:org.mitre.oval:tst:138184"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28116" version="4" class="vulnerability">
      <metadata>
        <title>ASP.NET information disclosure vulnerability - CVE-2015-1648 (MS15-041)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft .NET Framework 1.1</product>
          <product>Microsoft .NET Framework 2.0</product>
          <product>Microsoft .NET Framework 3.5.1</product>
          <product>Microsoft .NET Framework 4.0</product>
          <product>Microsoft .NET Framework 4.5</product>
          <product>Microsoft .NET Framework 4.5.1</product>
          <product>Microsoft .NET Framework 4.5.2</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-1648" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1648"/>
        <description>ASP.NET in Microsoft .NET Framework 1.1 SP1, 2.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, and 4.5.2, when the customErrors configuration is disabled, allows remote attackers to obtain sensitive configuration-file information via a crafted request, aka "ASP.NET Information Disclosure Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-04-17T11:54:36">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-04-23T10:27:19.660-04:00">DRAFT</status_change>
            <status_change date="2015-05-11T04:00:11.804-04:00">INTERIM</status_change>
            <status_change date="2015-06-01T04:00:16.386-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:28116 - Changed product names to represent versions consistently." date="2015-08-17T14:52:00.686-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-08-17T14:55:17.364-04:00">INTERIM</status_change>
          </dates>
          <status>INTERIM</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment=".NET 1.1 and vulnerable file">
          <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
          <criterion comment="Check if the version of System.web.dll is less than 1.1.4322.2515" test_ref="oval:org.mitre.oval:tst:138007"/>
          <extend_definition comment="Microsoft .NET Framework 1.1 Service Pack 1 is Installed" definition_ref="oval:org.mitre.oval:def:1834"/>
        </criteria>
        <criteria operator="AND" comment=".NET 2.0 and  XP / server 2003">
          <criteria operator="OR" comment="Either OS">
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 2.0 Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6158"/>
          <criteria operator="OR" comment="Either file version">
            <criterion comment="Check if the version of System.Web.dll is less than 2.0.50727.3668" test_ref="oval:org.mitre.oval:tst:138523"/>
            <criteria operator="AND" comment="ldr range for system.web.dll">
              <criterion comment="Check if the version of system.web.dll is less than 2.0.50727.8656" test_ref="oval:org.mitre.oval:tst:138479"/>
              <criterion comment="Check if the version of system.web.dll is greater than or equal to 2.0.50727.8600" test_ref="oval:org.mitre.oval:tst:138127"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment=".NET 2.0 and Vista / 2008">
          <criteria operator="OR" comment="Either OS">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 2.0 Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6158"/>
          <criteria operator="OR" comment="Either file version">
            <criterion comment="Check if the version of system.web.dll is less than 2.0.50727.4257" test_ref="oval:org.mitre.oval:tst:138599"/>
            <criteria operator="AND" comment="ldr range for system.web.dll">
              <criterion comment="Check if the version of system.web.dll is less than 2.0.50727.8653" test_ref="oval:org.mitre.oval:tst:138600"/>
              <criterion comment="Check if the version of system.web.dll is greater than or equal to 2.0.50727.7000" test_ref="oval:org.mitre.oval:tst:100649"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment=".NET 3.5 and Win 8 / server 2012">
          <criteria operator="OR" comment="Either OS">
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 3.5 SP1 is installed" definition_ref="oval:org.mitre.oval:def:12542"/>
          <criteria operator="OR" comment="Either file version">
            <criterion comment="Check if the version of the system.web.dll is less than 2.0.50727.6427" test_ref="oval:org.mitre.oval:tst:138417"/>
            <criteria operator="AND" comment="ldr range for system.web.dll">
              <criterion comment="Check if the version of system.web.dll is less than 2.0.50727.8653" test_ref="oval:org.mitre.oval:tst:138600"/>
              <criterion comment="Check if the version of system.web.dll is greater than or equal to 2.0.50727.8600" test_ref="oval:org.mitre.oval:tst:138127"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment=".NET and Win 8.1 / 2012 R2">
          <criteria operator="OR" comment="Either OS">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 3.5 SP1 is installed" definition_ref="oval:org.mitre.oval:def:12542"/>
          <criteria operator="OR" comment="Either file version">
            <criterion comment="Check if the version of system.web.dll is less than 2.0.50727.8015" test_ref="oval:org.mitre.oval:tst:138563"/>
            <criteria operator="AND" comment="ldr range for system.web.dll">
              <criterion comment="Check if the version of system.web.dll is less than 2.0.50727.8653" test_ref="oval:org.mitre.oval:tst:138600"/>
              <criterion comment="Check if the version of system.web.dll is greater than or equal to 2.0.50727.8600" test_ref="oval:org.mitre.oval:tst:138127"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment=".NET 3.5.1 and Win 7 / Server 2008 R2">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 3.5 SP1 is installed" definition_ref="oval:org.mitre.oval:def:12542"/>
          <criteria operator="OR" comment="Either file version">
            <criterion comment="Check if the version of system.web.dll is less than 2.0.50727.5491" test_ref="oval:org.mitre.oval:tst:137695"/>
            <criteria operator="AND" comment="ldr range for system.web.dll">
              <criterion comment="Check if the version of system.web.dll is less than 2.0.50727.8653" test_ref="oval:org.mitre.oval:tst:138600"/>
              <criterion comment="Check if the version of system.web.dll is greater than or equal to 2.0.50727.8600" test_ref="oval:org.mitre.oval:tst:138127"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment=".NET 4.0">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6749"/>
          <criteria operator="OR" comment="Either file version">
            <criterion comment="Check if the version of Setup.exe is less than 10.0.30319.1031" test_ref="oval:org.mitre.oval:tst:138047"/>
            <criteria operator="AND" comment="ldr range for system.web.dll">
              <criterion comment="Check if the version of Setup.exe is less than 10.0.30319.2056" test_ref="oval:org.mitre.oval:tst:138530"/>
              <criterion comment="Check if the version of Setup.exe is greater than or equal to 10.0.30319.2000" test_ref="oval:org.mitre.oval:tst:100142"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment=".NET 4.5/4.5.1 and Win Vista / Win 7 / server 2008 / Server 2008 R2">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Either .Net 4.5 / 4.5.1 / 4.5.2 and version">
            <extend_definition comment="Microsoft .NET Framework 4.5 is installed" definition_ref="oval:org.mitre.oval:def:15925"/>
            <extend_definition comment="Microsoft .NET Framework 4.5.1 is installed" definition_ref="oval:org.mitre.oval:def:22275"/>
            <extend_definition comment="Microsoft .NET Framework 4.5.2 is installed" definition_ref="oval:org.mitre.oval:def:26546"/>
          </criteria>
          <criteria operator="OR" comment="Either file version">
            <criterion comment="Check if the version of system.web.dll is less than 4.0.30319.34249" test_ref="oval:org.mitre.oval:tst:138462"/>
            <criteria operator="AND" comment="ldr range for system.wen.dll">
              <criterion comment="Check if the version of system.web.dll is less than 4.0.30319.36285" test_ref="oval:org.mitre.oval:tst:138259"/>
              <criterion comment="Check if the version of system.web.dll is greater than or equal to 4.0.30319.36000" test_ref="oval:org.mitre.oval:tst:138465"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment=".NET and Win 8 /Server 2012">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Either .Net 4.5 / 4.5.1 / 4.5.2 and version">
            <extend_definition comment="Microsoft .NET Framework 4.5 is installed" definition_ref="oval:org.mitre.oval:def:15925"/>
            <extend_definition comment="Microsoft .NET Framework 4.5.1 is installed" definition_ref="oval:org.mitre.oval:def:22275"/>
            <extend_definition comment="Microsoft .NET Framework 4.5.2 is installed" definition_ref="oval:org.mitre.oval:def:26546"/>
          </criteria>
          <criteria operator="OR" comment="Either file version">
            <criterion comment="Check if the version of system.web.dll is less than 4.0.30319.34248" test_ref="oval:org.mitre.oval:tst:138513"/>
            <criteria operator="AND" comment="ldr range for system.web.dll">
              <criterion comment="Check if the version of system.web.dll is less than 4.0.30319.36283" test_ref="oval:org.mitre.oval:tst:138171"/>
              <criterion comment="Check if the version of system.web.dll is greater than or equal to 4.0.30319.36000" test_ref="oval:org.mitre.oval:tst:138465"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment=".NET 4.5.1 / 4.5.2 and  Win 8.1 / Server 2012 R2">
          <criteria operator="OR" comment="Either .Net 4.5.1 / 4.5.2 version">
            <extend_definition comment="Microsoft .NET Framework 4.5.1 is installed" definition_ref="oval:org.mitre.oval:def:22275"/>
            <extend_definition comment="Microsoft .NET Framework 4.5.2 is installed" definition_ref="oval:org.mitre.oval:def:26546"/>
          </criteria>
          <criteria operator="OR" comment="Either OS">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criteria operator="OR" comment="Either file version">
            <criterion comment="Check if the version of system.web.dll is less than 4.0.30319.34248" test_ref="oval:org.mitre.oval:tst:138513"/>
            <criteria operator="AND" comment="ldr range for system.web.dll">
              <criterion comment="Check if the version of system.web.dll is less than 4.0.30319.36283" test_ref="oval:org.mitre.oval:tst:138171"/>
              <criterion comment="Check if the version of system.web.dll is greater than or equal to 4.0.30319.36000" test_ref="oval:org.mitre.oval:tst:138465"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28084" version="3" class="vulnerability">
      <metadata>
        <title>Graphics component information disclosure vulnerability - CVE-2014-6355 (MS14-085)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Vista</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-6355" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6355"/>
        <description>The Graphics Component in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 does not properly process JPEG images, which makes it easier for remote attackers to bypass the ASLR protection mechanism via a crafted web site, aka "Graphics Component Information Disclosure Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-12-12T09:19:02">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-12-16T00:31:57.318-05:00">DRAFT</status_change>
            <status_change date="2015-01-05T04:00:21.699-05:00">INTERIM</status_change>
            <status_change date="2015-01-26T04:00:24.183-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Check for Windows Server 2003 x86/x64 or Windows XP x86 and vulnerable file version">
          <criteria operator="OR" comment="Check for Windows Server 2003 x86/x64 or Windows XP x86">
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of gdiplus.dll is less than 5.2.6002.23535" test_ref="oval:org.mitre.oval:tst:135635"/>
        </criteria>
        <criteria operator="AND" comment="Vista / 2k8 + vulnerable file version">
          <criteria operator="OR" comment="Vista / 2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="Check for LDR/GDR">
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of windowscodecs.dll is less than 7.0.6002.23535" test_ref="oval:org.mitre.oval:tst:135554"/>
              <criterion comment="Check if the version of windowscodecs.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:135896"/>
            </criteria>
            <criterion comment="Check if the version of windowscodecs.dll is less than 7.0.6002.19227" test_ref="oval:org.mitre.oval:tst:135918"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / R2 + vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for LDR/GDR">
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of windowscodecs.dll is less than 6.2.9200.21283" test_ref="oval:org.mitre.oval:tst:135814"/>
              <criterion comment="Check if the version of windowscodecs.dll is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:135899"/>
            </criteria>
            <criterion comment="Check if the version of windowscodecs.dll is less than 6.2.9200.17170" test_ref="oval:org.mitre.oval:tst:135865"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8/2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of windowscodecs.dll is less than 6.2.9200.17170" test_ref="oval:org.mitre.oval:tst:135865"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of windowscodecs.dll is less than 6.2.9200.21283" test_ref="oval:org.mitre.oval:tst:135814"/>
              <criterion comment="Check if the version of windowscodecs.dll is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:135899"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1 / 2K12 R2and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of windowscodecs.dll is less than 6.3.9600.17483" test_ref="oval:org.mitre.oval:tst:135833"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28080" version="3" class="vulnerability">
      <metadata>
        <title>MSXML Remote Code Execution Vulnerability - CVE-2014-4118 (MS14-067)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft XML Core Services 3.0</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-4118" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4118"/>
        <description>XML Core Services (aka MSXML) 3.0 in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to execute arbitrary code or cause a denial of service (system-state corruption) via crafted XML content, aka "MSXML Remote Code Execution Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-14T09:35:14">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-11-17T17:01:01.543-05:00">DRAFT</status_change>
            <status_change date="2014-12-08T04:00:55.185-05:00">INTERIM</status_change>
            <status_change date="2014-12-29T04:00:29.590-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="2003/version">
          <extend_definition comment="Microsoft XML Core Services 3 is installed" definition_ref="oval:org.mitre.oval:def:415"/>
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of Msxml3.dll is less than 8.100.1056.0" test_ref="oval:org.mitre.oval:tst:135335"/>
        </criteria>
        <criteria operator="AND" comment="vista/2008/versions/Core services 3.0">
          <extend_definition comment="Microsoft XML Core Services 3 is installed" definition_ref="oval:org.mitre.oval:def:415"/>
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criterion comment="Check if the version of Msxml3.dll is less than 8.100.5009.0" test_ref="oval:org.mitre.oval:tst:135467"/>
        </criteria>
        <criteria operator="AND" comment="win7/2008 r2/versions/Core services 3.0">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of Msxml3.dll is less than 8.110.7601.18576" test_ref="oval:org.mitre.oval:tst:135472"/>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of Msxml3.dll is less than 8.110.7601.22782" test_ref="oval:org.mitre.oval:tst:135435"/>
              <criterion comment="Check if version of Msxml3.dll is greater than or equal to 8.110.7601.22000" test_ref="oval:org.mitre.oval:tst:79072"/>
            </criteria>
          </criteria>
          <extend_definition comment="Microsoft XML Core Services 3 is installed" definition_ref="oval:org.mitre.oval:def:415"/>
        </criteria>
        <criteria operator="AND" comment="win8/2012/versions">
          <extend_definition comment="Microsoft XML Core Services 3 is installed" definition_ref="oval:org.mitre.oval:def:415"/>
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of Msxml3.dll is less than 8.110.9200.17092" test_ref="oval:org.mitre.oval:tst:135230"/>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of Msxml3.dll is less than 8.110.9200.21211" test_ref="oval:org.mitre.oval:tst:135159"/>
              <criterion comment="Check if the version of msxml3.dll is greater than or equal to 8.110.9200.21000" test_ref="oval:org.mitre.oval:tst:135330"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="win 8.1/2012 r2/versions">
          <extend_definition comment="Microsoft XML Core Services 3 is installed" definition_ref="oval:org.mitre.oval:def:415"/>
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of Msxml3.dll is less than 8.110.9600.17324" test_ref="oval:org.mitre.oval:tst:135153"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28068" version="3" class="vulnerability">
      <metadata>
        <title>Microsoft windows kernel memory disclosure vulnerability - CVE-2015-1678 (MS15-051)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-1678" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1678"/>
        <description>The kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allow local users to bypass the ASLR protection mechanism via a crafted function call, aka "Microsoft Windows Kernel Memory Disclosure Vulnerability," a different vulnerability than CVE-2015-1676, CVE-2015-1677, CVE-2015-1679, and CVE-2015-1680.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-05-20T18:56:32">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-05-28T14:30:11.771-04:00">DRAFT</status_change>
            <status_change date="2015-06-15T04:00:12.565-04:00">INTERIM</status_change>
            <status_change date="2015-07-06T04:00:04.685-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Windows Server 2k3 and vulnerable file version">
          <criteria operator="OR" comment="Either OS">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of win32k.sys is less than 5.2.3790.5615" test_ref="oval:org.mitre.oval:tst:138664"/>
        </criteria>
        <criteria operator="AND" comment="Vista / 2k8 + vulnerable file version">
          <criteria operator="OR" comment="Vista / 2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:81723"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.0.6002.23680" test_ref="oval:org.mitre.oval:tst:138658"/>
            </criteria>
            <criterion comment="Check if the version of win32k.sys is less than 6.0.6002.19372" test_ref="oval:org.mitre.oval:tst:138686"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / R2 + vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.1.7601.23000" test_ref="oval:org.mitre.oval:tst:138862"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.23038" test_ref="oval:org.mitre.oval:tst:138649"/>
            </criteria>
            <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.18834" test_ref="oval:org.mitre.oval:tst:138724"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8/2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:115678"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.21457" test_ref="oval:org.mitre.oval:tst:138582"/>
            </criteria>
            <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.17343" test_ref="oval:org.mitre.oval:tst:138343"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1 / 2K12 R2and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of win32k.sys is less than 6.3.9600.17796" test_ref="oval:org.mitre.oval:tst:138198"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28056" version="4" class="vulnerability">
      <metadata>
        <title>TypeFilterLevel vulnerability - CVE-2014-4149 (MS14-072)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft .NET Framework 1.1</product>
          <product>Microsoft .NET Framework 2.0</product>
          <product>Microsoft .NET Framework 3.5.1</product>
          <product>Microsoft .NET Framework 4.0</product>
          <product>Microsoft .NET Framework 4.5</product>
          <product>Microsoft .NET Framework 4.5.1</product>
          <product>Microsoft .NET Framework 4.5.2</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-4149" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4149"/>
        <description>Microsoft .NET Framework 1.1 SP1, 2.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, and 4.5.2 does not properly perform TypeFilterLevel checks, which allows remote attackers to execute arbitrary code via crafted data to a .NET Remoting endpoint, aka "TypeFilterLevel Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-14T15:16:57.075+05:30">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-11-17T17:25:39.643-05:00">DRAFT</status_change>
            <status_change date="2014-12-08T04:00:53.895-05:00">INTERIM</status_change>
            <status_change date="2014-12-29T04:00:26.757-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:28056 - Changed product names to represent versions consistently." date="2015-08-17T14:52:00.686-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-08-17T14:55:19.832-04:00">INTERIM</status_change>
          </dates>
          <status>INTERIM</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment=".NET 1.1 and vulnerable file">
          <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
          <criterion comment="Check if the version of system.runtime.remoting.dll is less than 1.1.4322.2511" test_ref="oval:org.mitre.oval:tst:135048"/>
          <extend_definition comment="Microsoft .NET Framework 1.1 Service Pack 1 is Installed" definition_ref="oval:org.mitre.oval:def:1834"/>
        </criteria>
        <criteria operator="AND" comment=".NET 2.0 and  XP / server 2003">
          <criteria operator="OR" comment="Either OS">
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 2.0 Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6158"/>
          <criteria operator="OR" comment="Either file version">
            <criterion comment="Check if the version of system.runtime.remoting.dll is less than 2.0.50727.3664" test_ref="oval:org.mitre.oval:tst:135127"/>
            <criteria operator="AND" comment="ldr range for system.runtime.remoting.dll">
              <criterion comment="Check if the version of system.runtime.remoting.dll is less than 2.0.50727.8642" test_ref="oval:org.mitre.oval:tst:135376"/>
              <criterion comment="Check if the version of system.runtime.remoting.dll is greater than or equal to 2.0.50727.8600" test_ref="oval:org.mitre.oval:tst:114089"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment=".NET 2.0 and Vista / 2008">
          <criteria operator="OR" comment="Either OS">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 2.0 Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6158"/>
          <criteria operator="OR" comment="Either file version">
            <criterion comment="Check if the version of system.runtime.remoting.dll is less than 2.0.50727.4255" test_ref="oval:org.mitre.oval:tst:134767"/>
            <criteria operator="AND" comment="ldr range for system.runtime.remoting.dll">
              <criterion comment="Check if the version of system.runtime.remoting.dll is less than 2.0.50727.8641" test_ref="oval:org.mitre.oval:tst:135367"/>
              <criterion comment="Check if the version of system.runtime.remoting.dll is greater than or equal to 2.0.50727.8600" test_ref="oval:org.mitre.oval:tst:114089"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment=".NET 3.5 and Win 8 / server 2012">
          <criteria operator="OR" comment="Either OS">
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 3.5 SP1 is installed" definition_ref="oval:org.mitre.oval:def:12542"/>
          <criteria operator="OR" comment="Either file version">
            <criterion comment="Check if the version of system.runtime.remoting.dll is less than 2.0.50727.6424" test_ref="oval:org.mitre.oval:tst:135177"/>
            <criteria operator="AND" comment="ldr range for system.runtime.remoting.dll">
              <criterion comment="Check if the version of system.runtime.remoting.dll is less than 2.0.50727.8641" test_ref="oval:org.mitre.oval:tst:135367"/>
              <criterion comment="Check if the version of system.runtime.remoting.dll is greater than or equal to 2.0.50727.8600" test_ref="oval:org.mitre.oval:tst:114089"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment=".NET and Win 8.1 / 2012 R2">
          <criteria operator="OR" comment="Either OS">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 3.5 SP1 is installed" definition_ref="oval:org.mitre.oval:def:12542"/>
          <criteria operator="OR" comment="Either file version">
            <criterion comment="Check if the version of system.runtime.remoting.dll is less than 2.0.50727.8012" test_ref="oval:org.mitre.oval:tst:135204"/>
            <criteria operator="AND" comment="ldr range for system.runtime.remoting.dll">
              <criterion comment="Check if the version of system.runtime.remoting.dll is less than 2.0.50727.8641" test_ref="oval:org.mitre.oval:tst:135367"/>
              <criterion comment="Check if the version of system.runtime.remoting.dll is greater than or equal to 2.0.50727.8600" test_ref="oval:org.mitre.oval:tst:114089"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment=".NET 3.5.1 and Win 7 / Server 2008 R2">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 3.5 SP1 is installed" definition_ref="oval:org.mitre.oval:def:12542"/>
          <criteria operator="OR" comment="Either file version">
            <criterion comment="Check if the version of system.runtime.remoting.dll is less than 2.0.50727.5488" test_ref="oval:org.mitre.oval:tst:135034"/>
            <criteria operator="AND" comment="ldr range for system.runtime.remoting.dll">
              <criterion comment="Check if the version of system.runtime.remoting.dll is less than 2.0.50727.8641" test_ref="oval:org.mitre.oval:tst:135367"/>
              <criterion comment="Check if the version of system.runtime.remoting.dll is greater than or equal to 2.0.50727.8600" test_ref="oval:org.mitre.oval:tst:114089"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment=".NET 4.0">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6749"/>
          <criteria operator="OR" comment="Either file version">
            <criterion comment="Check if the version of system.runtime.remoting.dll is less than 4.0.30319.1030" test_ref="oval:org.mitre.oval:tst:135427"/>
            <criteria operator="AND" comment="ldr range for system.runtime.remoting.dll">
              <criterion comment="Check if the version of system.runtime.remoting.dll is less than 4.0.30319.2049" test_ref="oval:org.mitre.oval:tst:135401"/>
              <criterion comment="Check if the version of system.runtime.remoting.dll is greater than or equal to 4.0.30319.2000" test_ref="oval:org.mitre.oval:tst:113636"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment=".NET 4.5/4.5.1 and Win Vista / Win 7 / server 2008 / Server 2008 R2">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Either .Net 4.5 / 4.5.1 / 4.5.2 and version">
            <extend_definition comment="Microsoft .NET Framework 4.5 is installed" definition_ref="oval:org.mitre.oval:def:15925"/>
            <extend_definition comment="Microsoft .NET Framework 4.5.1 is installed" definition_ref="oval:org.mitre.oval:def:22275"/>
            <extend_definition comment="Microsoft .NET Framework 4.5.2 is installed" definition_ref="oval:org.mitre.oval:def:26546"/>
          </criteria>
          <criteria operator="OR" comment="Either file version">
            <criterion comment="Check if the version of system.runtime.remoting.dll is less than 4.0.30319.34245" test_ref="oval:org.mitre.oval:tst:135408"/>
            <criteria operator="AND" comment="ldr range for system.wen.dll">
              <criterion comment="Check if the version of system.runtime.remoting.dll is less than 4.0.30319.36257" test_ref="oval:org.mitre.oval:tst:135325"/>
              <criterion comment="Check if the version of system.runtime.remoting.dll is greater than or equal to 4.0.30319.36000" test_ref="oval:org.mitre.oval:tst:114135"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment=".NET and Win 8 /Server 2012">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Either .Net 4.5 / 4.5.1 / 4.5.2 and version">
            <extend_definition comment="Microsoft .NET Framework 4.5 is installed" definition_ref="oval:org.mitre.oval:def:15925"/>
            <extend_definition comment="Microsoft .NET Framework 4.5.1 is installed" definition_ref="oval:org.mitre.oval:def:22275"/>
            <extend_definition comment="Microsoft .NET Framework 4.5.2 is installed" definition_ref="oval:org.mitre.oval:def:26546"/>
          </criteria>
          <criteria operator="OR" comment="Either file version">
            <criterion comment="Check if the version of system.runtime.remoting.dll is less than 4.0.30319.34243" test_ref="oval:org.mitre.oval:tst:135009"/>
            <criteria operator="AND" comment="ldr range for system.runtime.remoting.dll">
              <criterion comment="Check if the version of system.runtime.remoting.dll is less than 4.0.30319.36255" test_ref="oval:org.mitre.oval:tst:135389"/>
              <criterion comment="Check if the version of system.runtime.remoting.dll is greater than or equal to 4.0.30319.36000" test_ref="oval:org.mitre.oval:tst:114135"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment=".NET 4.5.1 / 4.52 and  Win 8.1 / Server 2012 R2">
          <criteria operator="OR" comment="Either .Net 4.5.1 / 4.5.2 version">
            <extend_definition comment="Microsoft .NET Framework 4.5.1 is installed" definition_ref="oval:org.mitre.oval:def:22275"/>
            <extend_definition comment="Microsoft .NET Framework 4.5.2 is installed" definition_ref="oval:org.mitre.oval:def:26546"/>
          </criteria>
          <criteria operator="OR" comment="Either OS">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criteria operator="OR" comment="Either file version">
            <criterion comment="Check if the version of system.runtime.remoting.dll is less than 4.0.30319.34243" test_ref="oval:org.mitre.oval:tst:135009"/>
            <criteria operator="AND" comment="ldr range for mscorlib.dll">
              <criterion comment="Check if the version of system.runtime.remoting.dll is less than 4.0.30319.36255" test_ref="oval:org.mitre.oval:tst:135389"/>
              <criterion comment="Check if the version of system.runtime.remoting.dll is greater than or equal to 4.0.30319.36000" test_ref="oval:org.mitre.oval:tst:114135"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28046" version="5" class="vulnerability">
      <metadata>
        <title>Windows OLE automation array remote code execution vulnerability - CVE-2014-6332 (MS14-064)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Vista</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-6332" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6332"/>
        <description>OleAut32.dll in OLE in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to execute arbitrary code via a crafted web site, as demonstrated by an array-redimensioning attempt that triggers improper handling of a size value in the SafeArrayDimen function, aka "Windows OLE Automation Array Remote Code Execution Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-14T09:19:02">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-11-17T16:51:30.079-05:00">DRAFT</status_change>
            <status_change date="2014-12-08T04:00:53.465-05:00">INTERIM</status_change>
            <status_change date="2014-12-29T04:00:25.144-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Check for Windows Server 2003 x86/x64 or Windows XP x86 and vulnerable file version">
          <criteria operator="OR" comment="Check for Windows Server 2003 x86/x64 or Windows XP x86">
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="the version of oleaut32.dll is less than 5.2.3790.5464" test_ref="oval:org.mitre.oval:tst:135145"/>
        </criteria>
        <criteria operator="AND" comment="Vista / 2k8 + vulnerable file version">
          <criteria operator="OR" comment="Vista / 2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="Check for LDR/GDR">
            <criterion comment="Check if version of Packager.dll is less than 6.0.6002.19220" test_ref="oval:org.mitre.oval:tst:134817"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if version of Packager.dll is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:125246"/>
              <criterion comment="Check if version of Packager.dll is less than 6.0.6002.23527" test_ref="oval:org.mitre.oval:tst:134430"/>
            </criteria>
            <criteria operator="AND" comment="Check for LDR (Oleaut32.dll)">
              <criterion comment="Check if the the version of Oleaut32.dll is less than 6.0.6002.23523" test_ref="oval:org.mitre.oval:tst:135387"/>
              <criterion comment="Check if the version of Oleaut32.dll is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:135348"/>
            </criteria>
            <criterion comment="Check if the version of Oleaut32.dll is less than 6.0.6002.19216" test_ref="oval:org.mitre.oval:tst:135047"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / R2 + vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="Check for LDR/GDR">
            <criterion comment="Check if version of Packager.dll is less than 6.1.7601.18645" test_ref="oval:org.mitre.oval:tst:135398"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if version of Packager.dll is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:125217"/>
              <criterion comment="Check if version of Packager.dll is less than 6.1.7601.22853" test_ref="oval:org.mitre.oval:tst:134892"/>
            </criteria>
            <criteria operator="AND" comment="Check for LDR (Oleaut32.dll)">
              <criterion comment="Check if the version of Oleaut32.dll is less than 6.1.7601.22846" test_ref="oval:org.mitre.oval:tst:135363"/>
              <criterion comment="Check if the version of Oleaut32.dll is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:135416"/>
            </criteria>
            <criterion comment="Check if the version of Oleaut32.dll is less than 6.1.7601.18640" test_ref="oval:org.mitre.oval:tst:135320"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8/2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Packager.dll is less than 6.2.9200.21278" test_ref="oval:org.mitre.oval:tst:135137"/>
              <criterion comment="Check if the version of Packager.dll is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:124862"/>
            </criteria>
            <criteria operator="AND" comment="Check for LDR (Oleaut32.dll)">
              <criterion comment="Check if the version of Oleaut32.dll is less than 6.2.9200.21273" test_ref="oval:org.mitre.oval:tst:135117"/>
              <criterion comment="Check if the version of Oleaut32.dll is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:135377"/>
            </criteria>
            <criterion comment="Check if the version of Oleaut32.dll is less than 6.2.9200.17155" test_ref="oval:org.mitre.oval:tst:135036"/>
            <criterion comment="Check if the version of Packager.dll is less than 6.2.9200.17160" test_ref="oval:org.mitre.oval:tst:135423"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1 / 2K12 R2and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criteria operator="OR" comment="Either file version">
            <criterion comment="Check if the version of packager.dll is less than 6.3.9600.17408" test_ref="oval:org.mitre.oval:tst:135370"/>
            <criterion comment="Check if the version of Oleaut32.dll is less than 6.3.9600.17403" test_ref="oval:org.mitre.oval:tst:135178"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28018" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer cross-domain information disclosure vulnerability - CVE-2015-0070 (MS15-009)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
          <product>Microsoft Internet Explorer 6</product>
        </affected>
        <reference ref_id="CVE-2015-0070" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0070" source="CVE"/>
        <description>Microsoft Internet Explorer 6 through 11 allows remote attackers to read content from a different (1) domain or (2) zone via a crafted web site, aka "Internet Explorer Cross-domain Information Disclosure Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-02-13T10:59:59">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-02-16T13:12:02.795-05:00">DRAFT</status_change>
            <status_change date="2015-03-09T04:01:27.194-04:00">INTERIM</status_change>
            <status_change date="2015-03-30T04:00:10.708-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5508" test_ref="oval:org.mitre.oval:tst:137925"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21432" test_ref="oval:org.mitre.oval:tst:138027"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista / 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19281" test_ref="oval:org.mitre.oval:tst:138002"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23590" test_ref="oval:org.mitre.oval:tst:137924"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23644" test_ref="oval:org.mitre.oval:tst:137686"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19600" test_ref="oval:org.mitre.oval:tst:137706"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23655" test_ref="oval:org.mitre.oval:tst:137677"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18715" test_ref="oval:org.mitre.oval:tst:138039"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22921" test_ref="oval:org.mitre.oval:tst:137991"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16609" test_ref="oval:org.mitre.oval:tst:138073"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20725" test_ref="oval:org.mitre.oval:tst:137846"/>
            </criteria>
            <criterion comment="Check if the version of Jscript9.dll is less than 9.0.8112.16620" test_ref="oval:org.mitre.oval:tst:137873"/>
            <criteria operator="AND" comment="Jscript and LDR">
              <criterion comment="Check if the version of Jscript9.dll is less than 9.0.8112.20730" test_ref="oval:org.mitre.oval:tst:137974"/>
              <criterion comment="Check if the version of Jscript9.dll is greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:137868"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <criteria operator="AND" comment="Win 7/R2">
              <criteria operator="OR" comment="Win 7/R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17229" test_ref="oval:org.mitre.oval:tst:137987"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21345" test_ref="oval:org.mitre.oval:tst:137107"/>
                </criteria>
                <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.17241" test_ref="oval:org.mitre.oval:tst:137700"/>
                <criteria operator="AND" comment="Jscript.dll and LDR">
                  <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.21359" test_ref="oval:org.mitre.oval:tst:137021"/>
                  <criterion comment="Check if the version of Jscript9.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:137516"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 8/ 2012 R2">
              <criteria operator="OR" comment="Win 8/ 2012">
                <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
                <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
                <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17228" test_ref="oval:org.mitre.oval:tst:137876"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21345" test_ref="oval:org.mitre.oval:tst:137107"/>
                </criteria>
                <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.17241" test_ref="oval:org.mitre.oval:tst:137700"/>
                <criteria operator="AND" comment="Jscript.dll and LDR">
                  <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.21359" test_ref="oval:org.mitre.oval:tst:137021"/>
                  <criterion comment="Check if the version of Jscript9.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:137516"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/ 2k12 R2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7/ 2k8 R2/ 8.1/ 2k12 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criteria operator="OR" comment="either file">
                <criterion comment="Check if the version of Jscript9.dll is less than 11.0.9600.17640" test_ref="oval:org.mitre.oval:tst:137882"/>
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17631" test_ref="oval:org.mitre.oval:tst:137835"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27987" version="3" class="vulnerability">
      <metadata>
        <title>WTS remote code execution vulnerability - CVE-2015-0081 (MS15-020)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-0081" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0081"/>
        <description>Windows Text Services (WTS) in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to execute arbitrary code via a crafted (1) web site or (2) file, aka "WTS Remote Code Execution Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-03-16T12:40:27">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-03-17T10:49:15.398-04:00">DRAFT</status_change>
            <status_change date="2015-04-06T04:00:05.473-04:00">INTERIM</status_change>
            <status_change date="2015-04-27T04:00:12.324-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Windows 2003 and vulnerable file versions">
          <criteria operator="OR" comment="Win 2k3 (x86/x64/ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of msctf.dll is less than 5.2.3790.5528" test_ref="oval:org.mitre.oval:tst:138159"/>
        </criteria>
        <criteria operator="AND" comment="Vista /2k8 and vulnerable file versions">
          <criteria operator="OR" comment="Vista / 2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of msctf.dll is less than 6.0.6002.19296" test_ref="oval:org.mitre.oval:tst:138055"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of msctf.dll is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:138164"/>
              <criterion comment="Check if the version of msctf.dll is less than 6.0.6002.23606" test_ref="oval:org.mitre.oval:tst:138244"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 /2k8 R2 and vulnerable file versions">
          <criteria operator="OR" comment="Win 7 / 2k8 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of msctf.dll is less than 6.1.7601.18731" test_ref="oval:org.mitre.oval:tst:138228"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of msctf.dll is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:137811"/>
              <criterion comment="Check if the version of msctf.dll is less than 6.1.7601.22937" test_ref="oval:org.mitre.oval:tst:138300"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8 /2k12 and vulnerable file versions">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of msctf.dll is less than 6.2.9200.17243" test_ref="oval:org.mitre.oval:tst:138380"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of msctf.dll is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:138364"/>
              <criterion comment="Check if the version of msctf.dll is less than 6.2.9200.21361" test_ref="oval:org.mitre.oval:tst:138214"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1 /2k12 R2 and vulnerable file versions">
          <criteria operator="OR" comment="Win 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version msctf.dll is less than 6.3.9600.17664" test_ref="oval:org.mitre.oval:tst:138210"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27984" version="3" class="vulnerability">
      <metadata>
        <title>Microsoft IME (Japanese) elevation of privilege vulnerability - CVE-2014-4077 (MS14-078)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Input Method Editor Japanese</product>
          <product>Microsoft Office IME Japanese 2007</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-4077" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4077"/>
        <description>Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, and Office 2007 SP3, when IMJPDCT.EXE (aka IME for Japanese) is installed, allow remote attackers to bypass a sandbox protection mechanism via a crafted PDF document, aka "Microsoft IME (Japanese) Elevation of Privilege Vulnerability," as exploited in the wild in 2014.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-14T08:40:43">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-11-17T17:39:54.975-05:00">DRAFT</status_change>
            <status_change date="2014-12-08T04:00:52.349-05:00">INTERIM</status_change>
            <status_change date="2014-12-29T04:00:23.086-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="office 2007 IME Japanese and vulnerable version">
          <extend_definition comment="Microsoft Office 2007 IME Japanese is installed" definition_ref="oval:org.mitre.oval:def:27826"/>
          <criterion comment="Check if the version of Imjputyc.dll is less than 12.0.6704.5000 (Office IME japanese)" test_ref="oval:org.mitre.oval:tst:135443"/>
        </criteria>
        <criteria operator="AND" comment="OS and vulnerable version">
          <extend_definition comment="Microsoft Input method editor (IME) Japanese is installed" definition_ref="oval:org.mitre.oval:def:28268"/>
          <criteria operator="OR" comment="OS and Vuln file version">
            <criteria operator="AND" comment="2K3 and vulnerable file version">
              <criteria operator="OR" comment="Either OS">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of Imjputyc.dll is less than 8.1.7104.0" test_ref="oval:org.mitre.oval:tst:135444"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 + vulnerable file version">
              <criteria operator="OR" comment="Vista / 2K8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="GDR / LDR">
                <criterion comment="Check if the version of Imjputyc.dll is less than 10.0.6002.19154" test_ref="oval:org.mitre.oval:tst:135298"/>
                <criteria operator="AND" comment="LDR range">
                  <criterion comment="Check if the version of Imjputyc.dll is less than 10.0.6002.23459" test_ref="oval:org.mitre.oval:tst:135503"/>
                  <criterion comment="Check if the version of Imjputyc.dll is greater than or equal to 10.0.6002.23000" test_ref="oval:org.mitre.oval:tst:135478"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / 2008 R2 + vulnerable file version">
              <criteria operator="OR" comment="Win 7 / 2008 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="GDR / LDR">
                <criterion comment="Check if the version of Imjputyc.dll is less than 10.1.7601.18556" test_ref="oval:org.mitre.oval:tst:135473"/>
                <criteria operator="AND" comment="LDR range">
                  <criterion comment="Check if the version of Imjputyc.dll is less than 10.1.7601.22764" test_ref="oval:org.mitre.oval:tst:135470"/>
                  <criterion comment="Check if the version of Imjputyc.dll is greater than or equal to 10.1.7601.22000" test_ref="oval:org.mitre.oval:tst:134765"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28268" version="3" class="inventory">
      <metadata>
        <title>Microsoft Input method editor (IME) Japanese is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Vista</platform>
          <product>Microsoft Input Method Editor Japanese</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:ime:japanese"/>
        <description>Microsoft Input method editor (IME) Japanese is installed</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-14T07:13:04">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-11-17T17:39:53.705-05:00">DRAFT</status_change>
            <status_change date="2014-12-08T04:01:01.682-05:00">INTERIM</status_change>
            <status_change date="2014-12-29T04:00:41.706-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="Check if Microsoft IME (Japanese) is installed" test_ref="oval:org.mitre.oval:tst:134883"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27826" version="3" class="inventory">
      <metadata>
        <title>Microsoft Office 2007 IME Japanese is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Vista</platform>
          <product>Microsoft Office IME Japanese 2007</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:office:2007:::ime_japanese"/>
        <description>Microsoft Office 2007 IME Japanese is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-14T07:13:04">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-11-17T17:39:53.099-05:00">DRAFT</status_change>
            <status_change date="2014-12-08T04:00:50.352-05:00">INTERIM</status_change>
            <status_change date="2014-12-29T04:00:19.377-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="Check if Microsoft Office 2007 IME Japanese is installed" test_ref="oval:org.mitre.oval:tst:135203"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27977" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-0041 (MS15-009)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
          <product>Microsoft Internet Explorer 6</product>
        </affected>
        <reference ref_id="CVE-2015-0041" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0041" source="CVE"/>
        <description>Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-0017, CVE-2015-0020, CVE-2015-0022, CVE-2015-0026, CVE-2015-0030, CVE-2015-0031, and CVE-2015-0036.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-02-13T10:59:59">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-02-16T13:11:25.392-05:00">DRAFT</status_change>
            <status_change date="2015-03-09T04:01:26.618-04:00">INTERIM</status_change>
            <status_change date="2015-03-30T04:00:09.978-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5508" test_ref="oval:org.mitre.oval:tst:137925"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21432" test_ref="oval:org.mitre.oval:tst:138027"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista / 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19281" test_ref="oval:org.mitre.oval:tst:138002"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23590" test_ref="oval:org.mitre.oval:tst:137924"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23644" test_ref="oval:org.mitre.oval:tst:137686"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19600" test_ref="oval:org.mitre.oval:tst:137706"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23655" test_ref="oval:org.mitre.oval:tst:137677"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18715" test_ref="oval:org.mitre.oval:tst:138039"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22921" test_ref="oval:org.mitre.oval:tst:137991"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16609" test_ref="oval:org.mitre.oval:tst:138073"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20725" test_ref="oval:org.mitre.oval:tst:137846"/>
            </criteria>
            <criterion comment="Check if the version of Jscript9.dll is less than 9.0.8112.16620" test_ref="oval:org.mitre.oval:tst:137873"/>
            <criteria operator="AND" comment="Jscript and LDR">
              <criterion comment="Check if the version of Jscript9.dll is less than 9.0.8112.20730" test_ref="oval:org.mitre.oval:tst:137974"/>
              <criterion comment="Check if the version of Jscript9.dll is greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:137868"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <criteria operator="AND" comment="Win 7/R2">
              <criteria operator="OR" comment="Win 7/R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17229" test_ref="oval:org.mitre.oval:tst:137987"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21345" test_ref="oval:org.mitre.oval:tst:137107"/>
                </criteria>
                <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.17241" test_ref="oval:org.mitre.oval:tst:137700"/>
                <criteria operator="AND" comment="Jscript.dll and LDR">
                  <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.21359" test_ref="oval:org.mitre.oval:tst:137021"/>
                  <criterion comment="Check if the version of Jscript9.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:137516"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 8/ 2012 R2">
              <criteria operator="OR" comment="Win 8/ 2012">
                <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
                <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
                <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17228" test_ref="oval:org.mitre.oval:tst:137876"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21345" test_ref="oval:org.mitre.oval:tst:137107"/>
                </criteria>
                <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.17241" test_ref="oval:org.mitre.oval:tst:137700"/>
                <criteria operator="AND" comment="Jscript.dll and LDR">
                  <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.21359" test_ref="oval:org.mitre.oval:tst:137021"/>
                  <criterion comment="Check if the version of Jscript9.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:137516"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/ 2k12 R2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7/ 2k8 R2/ 8.1/ 2k12 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criteria operator="OR" comment="either file">
                <criterion comment="Check if the version of Jscript9.dll is less than 11.0.9600.17640" test_ref="oval:org.mitre.oval:tst:137882"/>
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17631" test_ref="oval:org.mitre.oval:tst:137835"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27957" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-0042 (MS15-009)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-0042" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0042" source="CVE"/>
        <description>Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-0038 and CVE-2015-0046.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-02-13T10:59:59">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-02-16T13:11:47.830-05:00">DRAFT</status_change>
            <status_change date="2015-03-09T04:01:25.792-04:00">INTERIM</status_change>
            <status_change date="2015-03-30T04:00:09.257-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16609" test_ref="oval:org.mitre.oval:tst:138073"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20725" test_ref="oval:org.mitre.oval:tst:137846"/>
            </criteria>
            <criterion comment="Check if the version of Jscript9.dll is less than 9.0.8112.16620" test_ref="oval:org.mitre.oval:tst:137873"/>
            <criteria operator="AND" comment="Jscript and LDR">
              <criterion comment="Check if the version of Jscript9.dll is less than 9.0.8112.20730" test_ref="oval:org.mitre.oval:tst:137974"/>
              <criterion comment="Check if the version of Jscript9.dll is greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:137868"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <criteria operator="AND" comment="Win 7/R2">
              <criteria operator="OR" comment="Win 7/R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17229" test_ref="oval:org.mitre.oval:tst:137987"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21345" test_ref="oval:org.mitre.oval:tst:137107"/>
                </criteria>
                <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.17241" test_ref="oval:org.mitre.oval:tst:137700"/>
                <criteria operator="AND" comment="Jscript.dll and LDR">
                  <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.21359" test_ref="oval:org.mitre.oval:tst:137021"/>
                  <criterion comment="Check if the version of Jscript9.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:137516"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 8/ 2012 R2">
              <criteria operator="OR" comment="Win 8/ 2012">
                <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
                <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
                <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17228" test_ref="oval:org.mitre.oval:tst:137876"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21345" test_ref="oval:org.mitre.oval:tst:137107"/>
                </criteria>
                <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.17241" test_ref="oval:org.mitre.oval:tst:137700"/>
                <criteria operator="AND" comment="Jscript.dll and LDR">
                  <criterion comment="Check if the version of Jscript9.dll is less than 10.0.9200.21359" test_ref="oval:org.mitre.oval:tst:137021"/>
                  <criterion comment="Check if the version of Jscript9.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:137516"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/ 2k12 R2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7/ 2k8 R2/ 8.1/ 2k12 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criteria operator="OR" comment="either file">
                <criterion comment="Check if the version of Jscript9.dll is less than 11.0.9600.17640" test_ref="oval:org.mitre.oval:tst:137882"/>
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17631" test_ref="oval:org.mitre.oval:tst:137835"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27932" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer XSS filter bypass vulnerability - CVE-2014-6365 (MS14-080)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2014-6365" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6365" source="CVE"/>
        <description>Microsoft Internet Explorer 8 through 11 allows remote attackers to bypass the XSS filter via a crafted attribute of an element in an HTML document, aka "Internet Explorer XSS Filter Bypass Vulnerability," a different vulnerability than CVE-2014-6328.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-12-12T10:59:59">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-12-16T00:09:58.737-05:00">DRAFT</status_change>
            <status_change date="2015-01-05T04:00:16.226-05:00">INTERIM</status_change>
            <status_change date="2015-01-26T04:00:17.011-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23642" test_ref="oval:org.mitre.oval:tst:135810"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19587" test_ref="oval:org.mitre.oval:tst:135653"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23642" test_ref="oval:org.mitre.oval:tst:135810"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18667" test_ref="oval:org.mitre.oval:tst:135861"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22874" test_ref="oval:org.mitre.oval:tst:134963"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16599" test_ref="oval:org.mitre.oval:tst:135591"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20715" test_ref="oval:org.mitre.oval:tst:135879"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17183" test_ref="oval:org.mitre.oval:tst:135488"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21299" test_ref="oval:org.mitre.oval:tst:135770"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17496" test_ref="oval:org.mitre.oval:tst:135858"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27923" version="3" class="vulnerability">
      <metadata>
        <title>Windows OLE remote code execution vulnerability - CVE-2014-6352 (MS14-064)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Vista</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-6352" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6352"/>
        <description>Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allow remote attackers to execute arbitrary code via a crafted OLE object, as exploited in the wild in October 2014 with a crafted PowerPoint document.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-14T09:19:02">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-11-17T16:51:32.554-05:00">DRAFT</status_change>
            <status_change date="2014-12-08T04:00:51.571-05:00">INTERIM</status_change>
            <status_change date="2014-12-29T04:00:21.713-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vista / 2k8 + vulnerable file version">
          <criteria operator="OR" comment="Vista / 2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="Check for LDR/GDR">
            <criterion comment="Check if version of Packager.dll is less than 6.0.6002.19220" test_ref="oval:org.mitre.oval:tst:134817"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if version of Packager.dll is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:125246"/>
              <criterion comment="Check if version of Packager.dll is less than 6.0.6002.23527" test_ref="oval:org.mitre.oval:tst:134430"/>
            </criteria>
            <criteria operator="AND" comment="Check for LDR (Oleaut32.dll)">
              <criterion comment="Check if the the version of Oleaut32.dll is less than 6.0.6002.23523" test_ref="oval:org.mitre.oval:tst:135387"/>
              <criterion comment="Check if the version of Oleaut32.dll is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:135348"/>
            </criteria>
            <criterion comment="Check if the version of Oleaut32.dll is less than 6.0.6002.19216" test_ref="oval:org.mitre.oval:tst:135047"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / R2 + vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="Check for LDR/GDR">
            <criterion comment="Check if version of Packager.dll is less than 6.1.7601.18645" test_ref="oval:org.mitre.oval:tst:135398"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if version of Packager.dll is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:125217"/>
              <criterion comment="Check if version of Packager.dll is less than 6.1.7601.22853" test_ref="oval:org.mitre.oval:tst:134892"/>
            </criteria>
            <criteria operator="AND" comment="Check for LDR (Oleaut32.dll)">
              <criterion comment="Check if the version of Oleaut32.dll is less than 6.1.7601.22846" test_ref="oval:org.mitre.oval:tst:135363"/>
              <criterion comment="Check if the version of Oleaut32.dll is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:135416"/>
            </criteria>
            <criterion comment="Check if the version of Oleaut32.dll is less than 6.1.7601.18640" test_ref="oval:org.mitre.oval:tst:135320"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8/2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Packager.dll is less than 6.2.9200.21278" test_ref="oval:org.mitre.oval:tst:135137"/>
              <criterion comment="Check if the version of Packager.dll is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:124862"/>
            </criteria>
            <criteria operator="AND" comment="Check for LDR (Oleaut32.dll)">
              <criterion comment="Check if the version of Oleaut32.dll is less than 6.2.9200.21273" test_ref="oval:org.mitre.oval:tst:135117"/>
              <criterion comment="Check if the version of Oleaut32.dll is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:135377"/>
            </criteria>
            <criterion comment="Check if the version of Oleaut32.dll is less than 6.2.9200.17155" test_ref="oval:org.mitre.oval:tst:135036"/>
            <criterion comment="Check if the version of Packager.dll is less than 6.2.9200.17160" test_ref="oval:org.mitre.oval:tst:135423"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1 / 2K12 R2and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criteria operator="OR" comment="Either file version">
            <criterion comment="Check if the version of packager.dll is less than 6.3.9600.17408" test_ref="oval:org.mitre.oval:tst:135370"/>
            <criterion comment="Check if the version of Oleaut32.dll is less than 6.3.9600.17403" test_ref="oval:org.mitre.oval:tst:135178"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27909" version="3" class="vulnerability">
      <metadata>
        <title>IIS Security feature bypass vulnerability - CVE-2014-4078 (MS14-076)</title>
        <affected family="windows">
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Information Services 8.0</product>
          <product>Microsoft Internet Information Services 8.5</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-4078" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4078"/>
        <description>The IP Security feature in Microsoft Internet Information Services (IIS) 8.0 and 8.5 does not properly process wildcard allow and deny rules for domains within the "IP Address and Domain Restrictions" list, which makes it easier for remote attackers to bypass an intended rule set via an HTTP request, aka "IIS Security Feature Bypass Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-14T09:56:34">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-11-17T17:37:59.406-05:00">DRAFT</status_change>
            <status_change date="2014-12-08T04:00:50.954-05:00">INTERIM</status_change>
            <status_change date="2014-12-29T04:00:20.617-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Win 8 / 2012 and IIS 8.0">
          <criteria operator="OR" comment="Either operating systems">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="GDR / LDR">
            <criterion comment="Check if the version of Iprestr.dll is less than 8.0.9200.17101" test_ref="oval:org.mitre.oval:tst:135360"/>
            <criteria operator="AND" comment="LDR range">
              <criterion comment="Check if the version of Iprestr.dll is less than 8.0.9200.21218" test_ref="oval:org.mitre.oval:tst:135482"/>
              <criterion comment="Check if the version of Iprestr.dll is greater than or equal to 8.0.9200.21000" test_ref="oval:org.mitre.oval:tst:135181"/>
            </criteria>
          </criteria>
          <extend_definition comment="Microsoft IIS 8.0 is installed" definition_ref="oval:org.mitre.oval:def:28016"/>
        </criteria>
        <criteria operator="AND" comment="Win 8.1 / 2K12 R2and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <extend_definition comment="Microsoft IIS 8.5 is installed" definition_ref="oval:org.mitre.oval:def:28171"/>
          <criterion comment="Check if the version of Iprestr.dll is less than 8.5.9600.17265" test_ref="oval:org.mitre.oval:tst:135342"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28171" version="5" class="inventory">
      <metadata>
        <title>Microsoft IIS 8.5 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft IIS 8.5</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:iis:8.5"/>
        <description>The application Microsoft IIS 8.5 is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-14T10:00:19">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-11-17T17:37:59.324-05:00">DRAFT</status_change>
            <status_change date="2014-12-08T04:00:57.181-05:00">INTERIM</status_change>
            <status_change date="2014-12-29T04:00:32.401-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:28171 - product info corrected" date="2015-04-15T12:33:00.646-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-04-15T12:36:19.367-04:00">INTERIM</status_change>
            <status_change date="2015-05-04T04:00:17.320-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="IIS Major Version equals 8" test_ref="oval:org.mitre.oval:tst:135431"/>
        <criterion comment="IIS Minor Version equals 5" test_ref="oval:org.mitre.oval:tst:27660"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28016" version="5" class="inventory">
      <metadata>
        <title>Microsoft IIS 8.0 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft IIS 8.0</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:iis:8.0"/>
        <description>The application Microsoft IIS 8.0 is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-14T10:00:19">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-11-17T17:37:59.035-05:00">DRAFT</status_change>
            <status_change date="2014-12-08T04:00:52.631-05:00">INTERIM</status_change>
            <status_change date="2014-12-29T04:00:23.637-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:28016 - product info corrected" date="2015-04-15T12:33:00.646-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-04-15T12:36:19.223-04:00">INTERIM</status_change>
            <status_change date="2015-05-04T04:00:17.173-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="IIS Major Version equals 8" test_ref="oval:org.mitre.oval:tst:135431"/>
        <criterion comment="IIS Minor Version equals 0" test_ref="oval:org.mitre.oval:tst:164"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27908" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-1667 (MS15-032)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-1667" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1667" source="CVE"/>
        <description>Microsoft Internet Explorer 8 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-04-21T10:59:59">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-04-24T09:24:15.343-04:00">DRAFT</status_change>
            <status_change date="2015-05-11T04:00:11.081-04:00">INTERIM</status_change>
            <status_change date="2015-06-01T04:00:15.771-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23671" test_ref="oval:org.mitre.oval:tst:138606"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19612" test_ref="oval:org.mitre.oval:tst:138331"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23671" test_ref="oval:org.mitre.oval:tst:138606"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18806" test_ref="oval:org.mitre.oval:tst:138424"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.23010" test_ref="oval:org.mitre.oval:tst:137911"/>
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.23000" test_ref="oval:org.mitre.oval:tst:138202"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16636" test_ref="oval:org.mitre.oval:tst:138537"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20750" test_ref="oval:org.mitre.oval:tst:137976"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17296" test_ref="oval:org.mitre.oval:tst:138031"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21413" test_ref="oval:org.mitre.oval:tst:138588"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17728" test_ref="oval:org.mitre.oval:tst:138275"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27899" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2015-1652 (MS15-032)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2015-1652" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1652" source="CVE"/>
        <description>Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-1666.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-04-21T10:59:59">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-04-24T09:24:11.748-04:00">DRAFT</status_change>
            <status_change date="2015-05-11T04:00:09.743-04:00">INTERIM</status_change>
            <status_change date="2015-06-01T04:00:14.803-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5569" test_ref="oval:org.mitre.oval:tst:138423"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21448" test_ref="oval:org.mitre.oval:tst:138618"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista / 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19334" test_ref="oval:org.mitre.oval:tst:138373"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23642" test_ref="oval:org.mitre.oval:tst:138546"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23671" test_ref="oval:org.mitre.oval:tst:138606"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19612" test_ref="oval:org.mitre.oval:tst:138331"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23671" test_ref="oval:org.mitre.oval:tst:138606"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18806" test_ref="oval:org.mitre.oval:tst:138424"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.23010" test_ref="oval:org.mitre.oval:tst:137911"/>
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.23000" test_ref="oval:org.mitre.oval:tst:138202"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16636" test_ref="oval:org.mitre.oval:tst:138537"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20750" test_ref="oval:org.mitre.oval:tst:137976"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17296" test_ref="oval:org.mitre.oval:tst:138031"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21413" test_ref="oval:org.mitre.oval:tst:138588"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17728" test_ref="oval:org.mitre.oval:tst:138275"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27897" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer elevation of privilege vulnerability - CVE-2014-6350 (MS14-065)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2014-6350" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6350" source="CVE"/>
        <description>Microsoft Internet Explorer 10 and 11 allows remote attackers to gain privileges via a crafted web site, aka "Internet Explorer Elevation of Privilege Vulnerability," a different vulnerability than CVE-2014-6349.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-18T10:59:59">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-11-20T23:04:15.603-05:00">DRAFT</status_change>
            <status_change date="2014-12-08T04:00:50.776-05:00">INTERIM</status_change>
            <status_change date="2014-12-29T04:00:20.204-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:135132 - States changed in accordance with MS14-065" date="2015-02-03T13:27:00.224-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-03T13:31:13.029-05:00">INTERIM</status_change>
            <status_change date="2015-02-23T04:01:06.317-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17173" test_ref="oval:org.mitre.oval:tst:135132"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21291" test_ref="oval:org.mitre.oval:tst:135567"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17420" test_ref="oval:org.mitre.oval:tst:135492"/>
            </criteria>
            <criteria operator="AND" comment="Win 8.1 / 2k12 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17416" test_ref="oval:org.mitre.oval:tst:135746"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27875" version="5" class="vulnerability">
      <metadata>
        <title>Microsoft SharePoint xss vulnerability – CVE-2015-1633 (MS15-022)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft SharePoint Foundation 2010</product>
          <product>Microsoft SharePoint Foundation 2013</product>
          <product>Microsoft SharePoint Server 2010</product>
          <product>Microsoft SharePoint Server 2013</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-1633" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1633"/>
        <description>Cross-site scripting (XSS) vulnerability in Microsoft SharePoint Foundation 2010 SP2, SharePoint Server 2010 SP2, SharePoint Foundation 2013 Gold and SP1, and SharePoint Server 2013 Gold and SP1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted request, aka "Microsoft SharePoint XSS Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-03-17T17:47:04">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-03-18T10:00:06.481-04:00">DRAFT</status_change>
            <status_change date="2015-04-06T04:00:04.604-04:00">INTERIM</status_change>
            <status_change date="2015-04-27T04:00:11.681-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:1569 - MS Bulletins - May 2015" date="2015-05-28T14:06:00.511-04:00">
              <contributor organization="SecPod Technologies">Kumarswamy S</contributor>
            </modified>
            <status_change date="2015-05-28T14:09:56.846-04:00">INTERIM</status_change>
            <status_change date="2015-06-15T04:00:12.182-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Sharepoint Server 2010 and vulnerable file version">
          <extend_definition comment="Microsoft Office SharePoint Server 2010 is installed." definition_ref="oval:org.mitre.oval:def:12880"/>
          <criterion comment="Check if the version of msoserver.dll is less than 14.0.7145.5000" test_ref="oval:org.mitre.oval:tst:138365"/>
        </criteria>
        <criteria operator="AND" comment="Sharepoint Foundation Server 2013 and vulnerable file version">
          <extend_definition comment="Microsoft SharePoint Foundation 2013 is installed" definition_ref="oval:org.mitre.oval:def:19090"/>
          <criterion comment="Check if the version of stswel.dll is less than 15.0.4701.1000" test_ref="oval:org.mitre.oval:tst:138170"/>
        </criteria>
        <criteria operator="AND" comment="Sharepoint Server 2013 and vulnerable file version">
          <extend_definition comment="Microsoft SharePoint Server 2013 is installed" definition_ref="oval:org.mitre.oval:def:16325"/>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of xlsrv.dll is less than 15.0.4701.1000" test_ref="oval:org.mitre.oval:tst:138254"/>
            <criterion comment="Check if the version of wwintl.dll is less than 15.0.4631.1000" test_ref="oval:org.mitre.oval:tst:138441"/>
            <criterion comment="Check if the version of vutils.dll is less than 15.0.4701.1000" test_ref="oval:org.mitre.oval:tst:138393"/>
            <criterion comment="Check if the version of microsoft.office.infopath.server.dll is less than 15.0.4701.1000" test_ref="oval:org.mitre.oval:tst:138339"/>
            <criterion comment="Check if the version of ascalc.dll is less than 15.0.4699.1000" test_ref="oval:org.mitre.oval:tst:138351"/>
            <criterion comment="Check if the version of msoserverintl.dll is less than 15.0.4697.1000" test_ref="oval:org.mitre.oval:tst:138449"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Sharepoint Foundation Server 2010 and vulnerable file version">
          <extend_definition comment="Microsoft SharePoint Foundation 2010 is installed" definition_ref="oval:org.mitre.oval:def:12224"/>
          <criterion comment="Check if the version of onetutil.dll is less than 14.0.7145.5000" test_ref="oval:org.mitre.oval:tst:138454"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27824" version="4" class="vulnerability">
      <metadata>
        <title>SharePoint elevation of privilege vulnerability - CVE-2014-4116 (MS14-073)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows Vista</platform>
          <product>Microsoft SharePoint Foundation 2010</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-4116" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4116"/>
        <description>Cross-site scripting (XSS) vulnerability in Microsoft SharePoint Foundation 2010 SP2 allows remote authenticated users to inject arbitrary web script or HTML via a modified list, aka "SharePoint Elevation of Privilege Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-14T10:39:40">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-11-17T17:29:43.671-05:00">DRAFT</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:1390 - November 2014 bulletins." date="2014-11-17T17:25:00.386-05:00">
              <contributor organization="SecPod Technologies">Kumarswamy S</contributor>
            </modified>
            <status_change date="2014-12-08T04:00:50.207-05:00">INTERIM</status_change>
            <status_change date="2014-12-29T04:00:19.171-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Microsoft SharePoint Foundation 2010 is installed" definition_ref="oval:org.mitre.oval:def:12224"/>
        <criterion comment="Check if the version of Onetutil.dll is less than 14.0.7137.5000" test_ref="oval:org.mitre.oval:tst:134500"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27794" version="5" class="vulnerability">
      <metadata>
        <title>Microsoft schannel remote code execution vulnerability - CVE-2014-6321 (MS14-066)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-6321" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6321"/>
        <description>Schannel in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to execute arbitrary code via crafted packets, aka "Microsoft Schannel Remote Code Execution Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-14T08:40:43">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-11-17T16:54:12.821-05:00">DRAFT</status_change>
            <status_change date="2014-12-08T04:00:49.726-05:00">INTERIM</status_change>
            <status_change date="2014-12-29T04:00:18.310-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:135297 - States changed in accordance with MS14-066" date="2015-02-03T13:31:00.917-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-03T13:32:49.343-05:00">INTERIM</status_change>
            <status_change date="2015-02-23T04:01:04.824-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Windows Server 2k3 and vulnerable file version">
          <criteria operator="OR" comment="Either OS">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of Schannnel.dll is less than 5.2.3790.5462" test_ref="oval:org.mitre.oval:tst:135027"/>
        </criteria>
        <criteria operator="AND" comment="Vista / 2k8 + vulnerable file version">
          <criteria operator="OR" comment="Vista / 2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of Schannnel.dll is less than 6.0.6002.23555" test_ref="oval:org.mitre.oval:tst:135415"/>
              <criterion comment="Check if the version of Schannel.dll is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:134478"/>
            </criteria>
            <criterion comment="Check if the version of Schannnel.dll is less than 6.0.6002.19247" test_ref="oval:org.mitre.oval:tst:135297"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / R2 + vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of Schannnel.dll is less than 6.1.7601.22814" test_ref="oval:org.mitre.oval:tst:135229"/>
              <criterion comment="Check if the version of schannel.dll is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:135418"/>
            </criteria>
            <criterion comment="Check if the version of Schannnel.dll is less than 6.1.7601.18606" test_ref="oval:org.mitre.oval:tst:135054"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8/2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of Schannnel.dll is less than 6.2.9200.21241" test_ref="oval:org.mitre.oval:tst:135152"/>
              <criterion comment="Check if the version of Schannel.dll is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:135406"/>
            </criteria>
            <criterion comment="Check if the version of Schannnel.dll is less than 6.2.9200.17124" test_ref="oval:org.mitre.oval:tst:135393"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1 / 2K12 R2and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of Schannnel.dll is less than 6.3.9600.17385" test_ref="oval:org.mitre.oval:tst:135346"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27768" version="3" class="vulnerability">
      <metadata>
        <title>Denial of service in Windows Kernel Mode Driver vulnerability - CVE-2014-6317 (MS14-079)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-6317" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6317"/>
        <description>Array index error in win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to cause a denial of service (reboot) via a crafted TrueType font, aka "Denial of Service in Windows Kernel Mode Driver Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-14T08:40:43">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-11-17T17:42:02.670-05:00">DRAFT</status_change>
            <status_change date="2014-12-08T04:00:49.272-05:00">INTERIM</status_change>
            <status_change date="2014-12-29T04:00:17.526-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Windows Server 2k3 and vulnerable file version">
          <criteria operator="OR" comment="Either OS">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of win32k.sys is less than 5.2.3790.5448" test_ref="oval:org.mitre.oval:tst:135249"/>
        </criteria>
        <criteria operator="AND" comment="Vista / 2k8 + vulnerable file version">
          <criteria operator="OR" comment="Vista / 2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of win32k.sys is less than 6.0.6002.19215" test_ref="oval:org.mitre.oval:tst:135422"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:81723"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.0.6002.23522" test_ref="oval:org.mitre.oval:tst:135446"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / R2 + vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.18618" test_ref="oval:org.mitre.oval:tst:135115"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:81763"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.22825" test_ref="oval:org.mitre.oval:tst:134694"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8/2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.17133" test_ref="oval:org.mitre.oval:tst:135502"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:115678"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.21250" test_ref="oval:org.mitre.oval:tst:135138"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1 / 2K12 R2and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of win32k.sys is less than 6.3.9600.17393" test_ref="oval:org.mitre.oval:tst:135314"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27743" version="3" class="vulnerability">
      <metadata>
        <title>WebDAV elevation of privilege vulnerability - CVE-2015-0011 (MS15-008)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Vista</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2015-0011" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0011"/>
        <description>mrxdav.sys (aka the WebDAV driver) in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to bypass an impersonation protection mechanism, and obtain privileges for redirection of WebDAV requests, via a crafted application, aka "WebDAV Elevation of Privilege Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2015-01-16T11:10:08">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-01-16T19:40:17.323-05:00">DRAFT</status_change>
            <status_change date="2015-02-02T04:00:11.062-05:00">INTERIM</status_change>
            <status_change date="2015-02-23T04:01:04.425-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Check for Windows Server 2003 x86/x64/ia64 and vulnerable file version">
          <criteria operator="OR" comment="Check for Windows Server 2003 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of Mrxdav.sys is less than 5.2.3790.5508" test_ref="oval:org.mitre.oval:tst:137458"/>
        </criteria>
        <criteria operator="AND" comment="Vista / 2k8 + vulnerable file version">
          <criteria operator="OR" comment="Vista / 2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of Mrxdav.sys is less than 6.0.6002.19273" test_ref="oval:org.mitre.oval:tst:137689"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Mrxdav.sys is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:137580"/>
              <criterion comment="Check if the version of Mrxdav.sys is less than 6.0.6002.23581" test_ref="oval:org.mitre.oval:tst:137584"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / R2 + vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of Mrxdav.sys is less than 6.1.7601.18706" test_ref="oval:org.mitre.oval:tst:137159"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Mrxdav.sys is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:137531"/>
              <criterion comment="Check if the version of Mrxdav.sys is less than 6.1.7601.22913" test_ref="oval:org.mitre.oval:tst:137072"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8 / 2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of Mrxdav.sys is less than 6.2.9200.17219" test_ref="oval:org.mitre.oval:tst:137126"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Mrxdav.sys is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:137739"/>
              <criterion comment="Check if the version of Mrxdav.sys is less than 6.2.9200.21317" test_ref="oval:org.mitre.oval:tst:137171"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1 / 2K12 R2 and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of Mrxdav.sys is less than 6.3.9600.17560" test_ref="oval:org.mitre.oval:tst:137442"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27704" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2014-6369 (MS14-080)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2014-6369" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6369" source="CVE"/>
        <description>Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-12-12T10:59:59">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-12-16T00:09:56.129-05:00">DRAFT</status_change>
            <status_change date="2015-01-05T04:00:12.173-05:00">INTERIM</status_change>
            <status_change date="2015-01-26T04:00:12.899-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16599" test_ref="oval:org.mitre.oval:tst:135591"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20715" test_ref="oval:org.mitre.oval:tst:135879"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17183" test_ref="oval:org.mitre.oval:tst:135488"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21299" test_ref="oval:org.mitre.oval:tst:135770"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17496" test_ref="oval:org.mitre.oval:tst:135858"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27601" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2014-6351 (MS14-065)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2014-6351" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6351" source="CVE"/>
        <description>Microsoft Internet Explorer 8 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-18T10:59:59">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-11-20T23:04:02.624-05:00">DRAFT</status_change>
            <status_change date="2014-12-08T04:00:46.770-05:00">INTERIM</status_change>
            <status_change date="2014-12-29T04:00:13.695-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:135132 - States changed in accordance with MS14-065" date="2015-02-03T13:27:00.224-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-03T13:31:11.794-05:00">INTERIM</status_change>
            <status_change date="2015-02-23T04:01:01.428-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 )">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23633" test_ref="oval:org.mitre.oval:tst:135078"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19575" test_ref="oval:org.mitre.oval:tst:135657"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23633" test_ref="oval:org.mitre.oval:tst:135078"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18631" test_ref="oval:org.mitre.oval:tst:135382"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22838" test_ref="oval:org.mitre.oval:tst:135196"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16592" test_ref="oval:org.mitre.oval:tst:135694"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20708" test_ref="oval:org.mitre.oval:tst:135680"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17173" test_ref="oval:org.mitre.oval:tst:135132"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21291" test_ref="oval:org.mitre.oval:tst:135567"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17420" test_ref="oval:org.mitre.oval:tst:135492"/>
            </criteria>
            <criteria operator="AND" comment="Win 8.1 / 2k12 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17416" test_ref="oval:org.mitre.oval:tst:135746"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27372" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2014-6337 (MS14-065)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference ref_id="CVE-2014-6337" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6337" source="CVE"/>
        <description>Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-18T10:59:59">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-11-20T23:04:00.311-05:00">DRAFT</status_change>
            <status_change date="2014-12-08T04:00:45.463-05:00">INTERIM</status_change>
            <status_change date="2014-12-29T04:00:10.621-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:27372 - States changed in accordance with MS14-065" date="2015-02-03T13:27:00.224-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-03T13:31:10.031-05:00">INTERIM</status_change>
            <status_change date="2015-02-23T04:00:59.833-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17173" test_ref="oval:org.mitre.oval:tst:135132"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21291" test_ref="oval:org.mitre.oval:tst:135567"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17420" test_ref="oval:org.mitre.oval:tst:135492"/>
            </criteria>
            <criteria operator="AND" comment="Win 8.1 / 2k12 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17416" test_ref="oval:org.mitre.oval:tst:135746"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27356" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability - CVE-2014-4143 (MS14-065)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
          <product>Microsoft Internet Explorer 6</product>
        </affected>
        <reference ref_id="CVE-2014-4143" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4143" source="CVE"/>
        <description>Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-6341.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-11-18T10:59:59">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-11-20T23:04:29.448-05:00">DRAFT</status_change>
            <status_change date="2014-12-08T04:00:44.873-05:00">INTERIM</status_change>
            <status_change date="2014-12-29T04:00:08.407-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:135132 - States changed in accordance with MS14-065" date="2015-02-03T13:27:00.224-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-03T13:31:12.726-05:00">INTERIM</status_change>
            <status_change date="2015-02-23T04:00:59.262-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23633" test_ref="oval:org.mitre.oval:tst:135078"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19575" test_ref="oval:org.mitre.oval:tst:135657"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23633" test_ref="oval:org.mitre.oval:tst:135078"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18631" test_ref="oval:org.mitre.oval:tst:135382"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22838" test_ref="oval:org.mitre.oval:tst:135196"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16592" test_ref="oval:org.mitre.oval:tst:135694"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20708" test_ref="oval:org.mitre.oval:tst:135680"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21415" test_ref="oval:org.mitre.oval:tst:135682"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista / 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19212" test_ref="oval:org.mitre.oval:tst:135209"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23517" test_ref="oval:org.mitre.oval:tst:135641"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17173" test_ref="oval:org.mitre.oval:tst:135132"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21291" test_ref="oval:org.mitre.oval:tst:135567"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17420" test_ref="oval:org.mitre.oval:tst:135492"/>
            </criteria>
            <criteria operator="AND" comment="Win 8.1 / 2k12 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17416" test_ref="oval:org.mitre.oval:tst:135746"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5458" test_ref="oval:org.mitre.oval:tst:135695"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27076" version="3" class="vulnerability">
      <metadata>
        <title>Win32k.sys elevation of privilege vulnerability - CVE-2014-4113 (MS14-058)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-4113" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4113"/>
        <description>win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges via a crafted application, as exploited in the wild in October 2014, aka "Win32k.sys Elevation of Privilege Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-10-17T08:40:43">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-10-17T17:49:57.819-04:00">DRAFT</status_change>
            <status_change date="2014-11-03T04:00:36.052-05:00">INTERIM</status_change>
            <status_change date="2014-11-24T04:02:06.596-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Windows Server 2k3 and vulnerable file version">
          <criteria operator="OR" comment="Either OS">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of win32k.sys is less than 5.2.3790.5445" test_ref="oval:org.mitre.oval:tst:124336"/>
        </criteria>
        <criteria operator="AND" comment="Vista / 2k8 + vulnerable file version">
          <criteria operator="OR" comment="Vista / 2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of win32k.sys is less than 6.0.6002.19198" test_ref="oval:org.mitre.oval:tst:125108"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:81723"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.0.6002.23504" test_ref="oval:org.mitre.oval:tst:124868"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / R2 + vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.18615" test_ref="oval:org.mitre.oval:tst:124383"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:81763"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.22823" test_ref="oval:org.mitre.oval:tst:125245"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8/2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.17130" test_ref="oval:org.mitre.oval:tst:125211"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:115678"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.21247" test_ref="oval:org.mitre.oval:tst:124497"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1 / 2K12 R2and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of win32k.sys is less than 6.3.9600.17353" test_ref="oval:org.mitre.oval:tst:124547"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27037" version="3" class="vulnerability">
      <metadata>
        <title>Internet explorer memory corruption vulnerability - CVE-2014-4126 (MS14-056)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-4126" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4126"/>
        <description>Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-10-17T20:45:43">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-10-17T17:28:36.753-04:00">DRAFT</status_change>
            <status_change date="2014-11-03T04:00:31.554-05:00">INTERIM</status_change>
            <status_change date="2014-11-24T04:01:49.270-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17116" test_ref="oval:org.mitre.oval:tst:125116"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21232" test_ref="oval:org.mitre.oval:tst:124505"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7 / 2k8 R2/8.1/2012 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17344" test_ref="oval:org.mitre.oval:tst:125090"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27003" version="3" class="vulnerability">
      <metadata>
        <title>Internet explorer ASLR bypass vulnerability - CVE-2014-4140 (MS14-056)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-4140" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4140"/>
        <description>Microsoft Internet Explorer 8 through 11 allows remote attackers to bypass the ASLR protection mechanism via a crafted web site, aka "Internet Explorer ASLR Bypass Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-10-17T20:45:43">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-10-17T17:28:49.855-04:00">DRAFT</status_change>
            <status_change date="2014-11-03T04:00:30.558-05:00">INTERIM</status_change>
            <status_change date="2014-11-24T04:01:41.032-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16584" test_ref="oval:org.mitre.oval:tst:125036"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20700" test_ref="oval:org.mitre.oval:tst:125029"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17116" test_ref="oval:org.mitre.oval:tst:125116"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21232" test_ref="oval:org.mitre.oval:tst:124505"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7 / 2k8 R2/8.1/2012 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17344" test_ref="oval:org.mitre.oval:tst:125090"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26997" version="3" class="vulnerability">
      <metadata>
        <title>Internet explorer memory corruption vulnerability - CVE-2014-4127 (MS14-056)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-4127" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4127"/>
        <description>Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-10-17T20:45:43">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-10-17T17:28:34.718-04:00">DRAFT</status_change>
            <status_change date="2014-11-03T04:00:30.199-05:00">INTERIM</status_change>
            <status_change date="2014-11-24T04:01:39.585-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5424" test_ref="oval:org.mitre.oval:tst:125117"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21409" test_ref="oval:org.mitre.oval:tst:125221"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista/2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19185" test_ref="oval:org.mitre.oval:tst:124464"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23489" test_ref="oval:org.mitre.oval:tst:125174"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23627" test_ref="oval:org.mitre.oval:tst:124999"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19569" test_ref="oval:org.mitre.oval:tst:125163"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23627" test_ref="oval:org.mitre.oval:tst:124999"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18595" test_ref="oval:org.mitre.oval:tst:124250"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22803" test_ref="oval:org.mitre.oval:tst:125113"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16584" test_ref="oval:org.mitre.oval:tst:125036"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20700" test_ref="oval:org.mitre.oval:tst:125029"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17116" test_ref="oval:org.mitre.oval:tst:125116"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21232" test_ref="oval:org.mitre.oval:tst:124505"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26918" version="3" class="vulnerability">
      <metadata>
        <title>Internet explorer memory corruption vulnerability - CVE-2014-4141 (MS14-052)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-4141" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4141"/>
        <description>Microsoft Internet Explorer 8 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-10-17T20:45:43">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-10-17T17:28:46.744-04:00">DRAFT</status_change>
            <status_change date="2014-11-03T04:00:25.888-05:00">INTERIM</status_change>
            <status_change date="2014-11-24T04:01:18.902-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23627" test_ref="oval:org.mitre.oval:tst:124999"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19569" test_ref="oval:org.mitre.oval:tst:125163"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23627" test_ref="oval:org.mitre.oval:tst:124999"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18595" test_ref="oval:org.mitre.oval:tst:124250"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22803" test_ref="oval:org.mitre.oval:tst:125113"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16584" test_ref="oval:org.mitre.oval:tst:125036"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20700" test_ref="oval:org.mitre.oval:tst:125029"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17116" test_ref="oval:org.mitre.oval:tst:125116"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21232" test_ref="oval:org.mitre.oval:tst:124505"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7 / 2k8 R2/8.1/2012 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17344" test_ref="oval:org.mitre.oval:tst:125090"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26910" version="4" class="vulnerability">
      <metadata>
        <title>.NET ClickOnce elevation of privilege vulnerability - CVE-2014-4073 (MS14-057)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft .NET Framework 2.0</product>
          <product>Microsoft .NET Framework 3.5.1</product>
          <product>Microsoft .NET Framework 4.0</product>
          <product>Microsoft .NET Framework 4.5</product>
          <product>Microsoft .NET Framework 4.5.1</product>
          <product>Microsoft .NET Framework 4.5.2</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-4073" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4073"/>
        <description>Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, and 4.5.2 processes unverified data during interaction with the ClickOnce installer, which allows remote attackers to gain privileges via vectors involving Internet Explorer, aka ".NET ClickOnce Elevation of Privilege Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-10-17T10:59:59">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-10-17T17:45:32.858-04:00">DRAFT</status_change>
            <status_change date="2014-11-03T04:00:23.204-05:00">INTERIM</status_change>
            <status_change date="2014-11-24T04:01:14.669-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:26910 - Changed product names to represent versions consistently." date="2015-08-17T14:52:00.686-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-08-17T14:55:19.056-04:00">INTERIM</status_change>
          </dates>
          <status>INTERIM</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment=".net 2.0 sp2/server 2003/versions">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 2.0 Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6158"/>
          <criteria operator="OR" comment="either file versions GDR/LDR">
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of System.deployment.dll is less than 2.0.50727.8641" test_ref="oval:org.mitre.oval:tst:125244"/>
              <criterion comment="Check if the version of system.deployment.dll is greater than or equal to 2.0.50727.8600" test_ref="oval:org.mitre.oval:tst:125071"/>
            </criteria>
            <criterion comment="Check if the version of system.deployment.dll is less than 2.0.50727.3663" test_ref="oval:org.mitre.oval:tst:125235"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Vista / 2k8 + vulnerable file version">
          <criteria operator="OR" comment="Vista / 2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="either file versions">
            <criterion comment="Check if the version of system.deployment.dll is less than 2.0.50727.4255" test_ref="oval:org.mitre.oval:tst:125162"/>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of System.deployment.dll is less than 2.0.50727.8641" test_ref="oval:org.mitre.oval:tst:125244"/>
              <criterion comment="Check if the version of system.deployment.dll is greater than or equal to 2.0.50727.8600" test_ref="oval:org.mitre.oval:tst:125071"/>
            </criteria>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 2.0 Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6158"/>
        </criteria>
        <criteria operator="AND" comment="Win 8/2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="either file versions">
            <criterion comment="Check if the version of system.deployment.dll is less than 2.0.50727.6424" test_ref="oval:org.mitre.oval:tst:124755"/>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of System.deployment.dll is less than 2.0.50727.8641" test_ref="oval:org.mitre.oval:tst:125244"/>
              <criterion comment="Check if the version of system.deployment.dll is greater than or equal to 2.0.50727.8600" test_ref="oval:org.mitre.oval:tst:125071"/>
            </criteria>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 3.5 SP1 is installed" definition_ref="oval:org.mitre.oval:def:12542"/>
        </criteria>
        <criteria operator="AND" comment=".net 3.5.1/win 8.1/server 2012 r2/versions">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 3.5 SP1 is installed" definition_ref="oval:org.mitre.oval:def:12542"/>
          <criteria operator="OR" comment="either file versions">
            <criterion comment="Check if the version of system.deployment.dll is less than 2.0.50727.8012" test_ref="oval:org.mitre.oval:tst:124677"/>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of System.deployment.dll is less than 2.0.50727.8641" test_ref="oval:org.mitre.oval:tst:125244"/>
              <criterion comment="Check if the version of system.deployment.dll is greater than or equal to 2.0.50727.8600" test_ref="oval:org.mitre.oval:tst:125071"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / R2 + vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
          </criteria>
          <criteria operator="OR" comment="either file versions">
            <criterion comment="Check if the version of system.deployment.dll is less than 2.0.50727.5488" test_ref="oval:org.mitre.oval:tst:124855"/>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of System.deployment.dll is less than 2.0.50727.8641" test_ref="oval:org.mitre.oval:tst:125244"/>
              <criterion comment="Check if the version of system.deployment.dll is greater than or equal to 2.0.50727.8600" test_ref="oval:org.mitre.oval:tst:125071"/>
            </criteria>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 3.5 SP1 is installed" definition_ref="oval:org.mitre.oval:def:12542"/>
        </criteria>
        <criteria operator="AND" comment=".net 4.0/win server 2003/vista/server 2008/Win 7/ server 2008 R2 and vuln versions">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6749"/>
          <criteria operator="OR" comment="GDR/LDR">
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of system.deployment.dll is less than 4.0.30319.2048" test_ref="oval:org.mitre.oval:tst:125121"/>
              <criterion comment="Check if the version of system.deployment.dll is greater than or equal to 4.0.30319.2000" test_ref="oval:org.mitre.oval:tst:124753"/>
            </criteria>
            <criterion comment="Check if the version of system.deployment.dll is less than 4.0.30319.1029" test_ref="oval:org.mitre.oval:tst:125047"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment=".net 4.5/4.5.1/4.5.2/vista/server 2008/win 7/server 2008 R2/versions">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="4.5/4.5.1/4.5.2">
            <extend_definition comment="Microsoft .NET Framework 4.5 is installed" definition_ref="oval:org.mitre.oval:def:15925"/>
            <extend_definition comment="Microsoft .NET Framework 4.5.1 is installed" definition_ref="oval:org.mitre.oval:def:22275"/>
            <extend_definition comment="Microsoft .NET Framework 4.5.2 is installed" definition_ref="oval:org.mitre.oval:def:26546"/>
          </criteria>
          <criteria operator="OR" comment="LDR / GDR range">
            <criterion comment="Check if the version of system.deployment.dll is less than 4.0.30319.34244" test_ref="oval:org.mitre.oval:tst:124990"/>
            <criteria operator="AND" comment="LDR range">
              <criterion comment="Check if the version of system.deployment.dll is less than 4.0.30319.36256" test_ref="oval:org.mitre.oval:tst:125179"/>
              <criterion comment="Check if the version of system.deployment.dll is greater than or equal to 4.0.30319.36000" test_ref="oval:org.mitre.oval:tst:125206"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1/2k12 R2 and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criteria operator="OR" comment="4.5.1/4.5.2">
            <extend_definition comment="Microsoft .NET Framework 4.5.1 is installed" definition_ref="oval:org.mitre.oval:def:22275"/>
            <extend_definition comment="Microsoft .NET Framework 4.5.2 is installed" definition_ref="oval:org.mitre.oval:def:26546"/>
          </criteria>
          <criteria operator="OR" comment="either file versions">
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of system.deployment.dll is less than 4.0.30319.36255" test_ref="oval:org.mitre.oval:tst:125063"/>
              <criterion comment="Check if the version of system.deployment.dll is greater than or equal to 4.0.30319.36000" test_ref="oval:org.mitre.oval:tst:125206"/>
            </criteria>
            <criterion comment="Check if the version of system.deployment.dll is less than 4.0.30319.34243" test_ref="oval:org.mitre.oval:tst:125250"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment=".net 4.5/4.5.1/4.5.2/win 8/server 2012/versions">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="4.5/4.5.1/4.5.2">
            <extend_definition comment="Microsoft .NET Framework 4.5 is installed" definition_ref="oval:org.mitre.oval:def:15925"/>
            <extend_definition comment="Microsoft .NET Framework 4.5.1 is installed" definition_ref="oval:org.mitre.oval:def:22275"/>
            <extend_definition comment="Microsoft .NET Framework 4.5.2 is installed" definition_ref="oval:org.mitre.oval:def:26546"/>
          </criteria>
          <criteria operator="OR" comment="either file versions">
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of system.deployment.dll is less than 4.0.30319.36255" test_ref="oval:org.mitre.oval:tst:125063"/>
              <criterion comment="Check if the version of system.deployment.dll is greater than or equal to 4.0.30319.36000" test_ref="oval:org.mitre.oval:tst:125206"/>
            </criteria>
            <criterion comment="Check if the version of system.deployment.dll is less than 4.0.30319.34243" test_ref="oval:org.mitre.oval:tst:125250"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26903" version="3" class="vulnerability">
      <metadata>
        <title>.NET ASLR vulnerability  - CVE-2014-4122 (MS14-057)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft .NET Framework 2.0</product>
          <product>Microsoft .NET Framework 3.5.1</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-4122" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4122"/>
        <description>Microsoft .NET Framework 2.0 SP2, 3.5, and 3.5.1 omits the ASLR protection mechanism, which allows remote attackers to obtain potentially sensitive information about memory addresses by leveraging the predictability of an executable image's location, aka ".NET ASLR Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-10-17T10:59:59">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-10-17T17:45:35.478-04:00">DRAFT</status_change>
            <status_change date="2014-11-03T04:00:22.952-05:00">INTERIM</status_change>
            <status_change date="2014-11-24T04:01:13.490-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vista / 2k8 + vulnerable file version">
          <criteria operator="OR" comment="Vista / 2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criterion comment="Check if the version of mscorie.dll is less than 2.0.50727.4252" test_ref="oval:org.mitre.oval:tst:125200"/>
          <extend_definition comment="Microsoft .NET Framework 2.0 Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6158"/>
        </criteria>
        <criteria operator="AND" comment="Win 8/2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criterion comment="Check if the version of mscorie.dll is less than 2.0.50727.6419" test_ref="oval:org.mitre.oval:tst:125164"/>
          <extend_definition comment="Microsoft .NET Framework 3.5 SP1 is installed" definition_ref="oval:org.mitre.oval:def:12542"/>
        </criteria>
        <criteria operator="AND" comment=".net 3.5.1/win 8.1/server 2012 r2/versions">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 3.5 SP1 is installed" definition_ref="oval:org.mitre.oval:def:12542"/>
          <criterion comment="Check if the version of mscorie.dll is less than 2.0.50727.8008" test_ref="oval:org.mitre.oval:tst:124856"/>
        </criteria>
        <criteria operator="AND" comment="Win 7 / R2 + vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
          </criteria>
          <criterion comment="Check if the version of mscorie.dll is less than 2.0.50727.5483" test_ref="oval:org.mitre.oval:tst:124996"/>
          <extend_definition comment="Microsoft .NET Framework 3.5 SP1 is installed" definition_ref="oval:org.mitre.oval:def:12542"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26879" version="3" class="vulnerability">
      <metadata>
        <title>Internet explorer memory corruption vulnerability - CVE-2014-4093 (MS14-052)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <product>Microsoft Internet Explorer 10</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-4093" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4093"/>
        <description>Microsoft Internet Explorer 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-4084.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-09-12T20:45:43">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-09-17T10:54:50.738-04:00">DRAFT</status_change>
            <status_change date="2014-10-06T04:04:11.038-04:00">INTERIM</status_change>
            <status_change date="2014-10-27T04:01:45.409-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
        <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
          <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
          <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
          <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
          <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
          <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
        </criteria>
        <criteria operator="OR" comment="Check for vulnerable versions">
          <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17088" test_ref="oval:org.mitre.oval:tst:123567"/>
          <criteria operator="AND" comment="Check for LDR">
            <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21207" test_ref="oval:org.mitre.oval:tst:123452"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26862" version="3" class="vulnerability">
      <metadata>
        <title>Internet explorer memory corruption vulnerability - CVE-2014-4082 (MS14-052)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-4082" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4082"/>
        <description>Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-09-12T20:45:43">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-09-17T10:54:01.071-04:00">DRAFT</status_change>
            <status_change date="2014-10-06T04:04:10.375-04:00">INTERIM</status_change>
            <status_change date="2014-10-27T04:01:42.851-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5413" test_ref="oval:org.mitre.oval:tst:123102"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21408" test_ref="oval:org.mitre.oval:tst:123204"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista/2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19165" test_ref="oval:org.mitre.oval:tst:123599"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23470" test_ref="oval:org.mitre.oval:tst:123011"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23619" test_ref="oval:org.mitre.oval:tst:123007"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19561" test_ref="oval:org.mitre.oval:tst:123464"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23619" test_ref="oval:org.mitre.oval:tst:123007"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18571" test_ref="oval:org.mitre.oval:tst:123348"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22777" test_ref="oval:org.mitre.oval:tst:123326"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16575" test_ref="oval:org.mitre.oval:tst:122615"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20691" test_ref="oval:org.mitre.oval:tst:123605"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17088" test_ref="oval:org.mitre.oval:tst:123567"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21207" test_ref="oval:org.mitre.oval:tst:123452"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26855" version="3" class="vulnerability">
      <metadata>
        <title>Internet explorer memory corruption vulnerability - CVE-2014-4088 (MS14-052)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-4088" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4088"/>
        <description>Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-2799, CVE-2014-4059, CVE-2014-4065, CVE-2014-4079, CVE-2014-4081, CVE-2014-4083, CVE-2014-4085, CVE-2014-4090, CVE-2014-4094, CVE-2014-4097, CVE-2014-4100, CVE-2014-4103, CVE-2014-4104, CVE-2014-4105, CVE-2014-4106, CVE-2014-4107, CVE-2014-4108, CVE-2014-4109, CVE-2014-4110, and CVE-2014-4111.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-09-12T20:45:43">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-09-17T10:54:22.289-04:00">DRAFT</status_change>
            <status_change date="2014-10-06T04:04:09.684-04:00">INTERIM</status_change>
            <status_change date="2014-10-27T04:01:42.072-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5413" test_ref="oval:org.mitre.oval:tst:123102"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21408" test_ref="oval:org.mitre.oval:tst:123204"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista/2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19165" test_ref="oval:org.mitre.oval:tst:123599"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23470" test_ref="oval:org.mitre.oval:tst:123011"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23619" test_ref="oval:org.mitre.oval:tst:123007"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19561" test_ref="oval:org.mitre.oval:tst:123464"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23619" test_ref="oval:org.mitre.oval:tst:123007"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18571" test_ref="oval:org.mitre.oval:tst:123348"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22777" test_ref="oval:org.mitre.oval:tst:123326"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16575" test_ref="oval:org.mitre.oval:tst:122615"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20691" test_ref="oval:org.mitre.oval:tst:123605"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17088" test_ref="oval:org.mitre.oval:tst:123567"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21207" test_ref="oval:org.mitre.oval:tst:123452"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7, 2k8 r2, win 8 or 2k12 r2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vuln file version">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17280" test_ref="oval:org.mitre.oval:tst:123331"/>
            </criteria>
            <criteria operator="AND" comment="Win 8 / 2k12 r2 and vuln file version">
              <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17278" test_ref="oval:org.mitre.oval:tst:123432"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26850" version="3" class="vulnerability">
      <metadata>
        <title>Internet explorer memory corruption vulnerability - CVE-2014-4128 (MS14-056)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-4128" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4128"/>
        <description>Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-10-17T20:45:43">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-10-17T17:28:52.859-04:00">DRAFT</status_change>
            <status_change date="2014-11-03T04:00:21.745-05:00">INTERIM</status_change>
            <status_change date="2014-11-24T04:01:00.404-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5424" test_ref="oval:org.mitre.oval:tst:125117"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21409" test_ref="oval:org.mitre.oval:tst:125221"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista/2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19185" test_ref="oval:org.mitre.oval:tst:124464"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23489" test_ref="oval:org.mitre.oval:tst:125174"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23627" test_ref="oval:org.mitre.oval:tst:124999"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19569" test_ref="oval:org.mitre.oval:tst:125163"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23627" test_ref="oval:org.mitre.oval:tst:124999"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18595" test_ref="oval:org.mitre.oval:tst:124250"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22803" test_ref="oval:org.mitre.oval:tst:125113"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16584" test_ref="oval:org.mitre.oval:tst:125036"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20700" test_ref="oval:org.mitre.oval:tst:125029"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17116" test_ref="oval:org.mitre.oval:tst:125116"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21232" test_ref="oval:org.mitre.oval:tst:124505"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7 / 2k8 R2/8.1/2012 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17344" test_ref="oval:org.mitre.oval:tst:125090"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26849" version="3" class="vulnerability">
      <metadata>
        <title>Internet explorer memory corruption vulnerability - CVE-2014-4065 (MS14-052)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-4065" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4065"/>
        <description>Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-2799, CVE-2014-4059, CVE-2014-4079, CVE-2014-4081, CVE-2014-4083, CVE-2014-4085, CVE-2014-4088, CVE-2014-4090, CVE-2014-4094, CVE-2014-4097, CVE-2014-4100, CVE-2014-4103, CVE-2014-4104, CVE-2014-4105, CVE-2014-4106, CVE-2014-4107, CVE-2014-4108, CVE-2014-4109, CVE-2014-4110, and CVE-2014-4111.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-09-12T20:45:43">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-09-17T10:54:42.580-04:00">DRAFT</status_change>
            <status_change date="2014-10-06T04:04:09.339-04:00">INTERIM</status_change>
            <status_change date="2014-10-27T04:01:41.553-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5413" test_ref="oval:org.mitre.oval:tst:123102"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21408" test_ref="oval:org.mitre.oval:tst:123204"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista/2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19165" test_ref="oval:org.mitre.oval:tst:123599"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23470" test_ref="oval:org.mitre.oval:tst:123011"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23619" test_ref="oval:org.mitre.oval:tst:123007"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19561" test_ref="oval:org.mitre.oval:tst:123464"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23619" test_ref="oval:org.mitre.oval:tst:123007"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18571" test_ref="oval:org.mitre.oval:tst:123348"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22777" test_ref="oval:org.mitre.oval:tst:123326"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16575" test_ref="oval:org.mitre.oval:tst:122615"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20691" test_ref="oval:org.mitre.oval:tst:123605"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17088" test_ref="oval:org.mitre.oval:tst:123567"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21207" test_ref="oval:org.mitre.oval:tst:123452"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7, 2k8 r2, win 8 or 2k12 r2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vuln file version">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17280" test_ref="oval:org.mitre.oval:tst:123331"/>
            </criteria>
            <criteria operator="AND" comment="Win 8 / 2k12 r2 and vuln file version">
              <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17278" test_ref="oval:org.mitre.oval:tst:123432"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26846" version="3" class="vulnerability">
      <metadata>
        <title>Internet explorer memory corruption vulnerability - CVE-2014-4081 (MS14-052)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-4081" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4081"/>
        <description>Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-2799, CVE-2014-4059, CVE-2014-4065, CVE-2014-4079, CVE-2014-4083, CVE-2014-4085, CVE-2014-4088, CVE-2014-4090, CVE-2014-4094, CVE-2014-4097, CVE-2014-4100, CVE-2014-4103, CVE-2014-4104, CVE-2014-4105, CVE-2014-4106, CVE-2014-4107, CVE-2014-4108, CVE-2014-4109, CVE-2014-4110, and CVE-2014-4111.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-09-12T20:45:43">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-09-17T10:54:04.714-04:00">DRAFT</status_change>
            <status_change date="2014-10-06T04:04:08.906-04:00">INTERIM</status_change>
            <status_change date="2014-10-27T04:01:41.016-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5413" test_ref="oval:org.mitre.oval:tst:123102"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21408" test_ref="oval:org.mitre.oval:tst:123204"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista/2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19165" test_ref="oval:org.mitre.oval:tst:123599"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23470" test_ref="oval:org.mitre.oval:tst:123011"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23619" test_ref="oval:org.mitre.oval:tst:123007"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19561" test_ref="oval:org.mitre.oval:tst:123464"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23619" test_ref="oval:org.mitre.oval:tst:123007"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18571" test_ref="oval:org.mitre.oval:tst:123348"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22777" test_ref="oval:org.mitre.oval:tst:123326"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16575" test_ref="oval:org.mitre.oval:tst:122615"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20691" test_ref="oval:org.mitre.oval:tst:123605"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17088" test_ref="oval:org.mitre.oval:tst:123567"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21207" test_ref="oval:org.mitre.oval:tst:123452"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7, 2k8 r2, win 8 or 2k12 r2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vuln file version">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17280" test_ref="oval:org.mitre.oval:tst:123331"/>
            </criteria>
            <criteria operator="AND" comment="Win 8 / 2k12 r2 and vuln file version">
              <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17278" test_ref="oval:org.mitre.oval:tst:123432"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26815" version="3" class="vulnerability">
      <metadata>
        <title>Internet explorer memory corruption vulnerability - CVE-2014-4108 (MS14-052)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-4108" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4108"/>
        <description>Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-2799, CVE-2014-4059, CVE-2014-4065, CVE-2014-4079, CVE-2014-4081, CVE-2014-4083, CVE-2014-4085, CVE-2014-4088, CVE-2014-4090, CVE-2014-4094, CVE-2014-4097, CVE-2014-4100, CVE-2014-4103, CVE-2014-4104, CVE-2014-4105, CVE-2014-4106, CVE-2014-4107, CVE-2014-4109, CVE-2014-4110, and CVE-2014-4111.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-09-12T20:45:43">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-09-17T10:54:14.215-04:00">DRAFT</status_change>
            <status_change date="2014-10-06T04:04:07.710-04:00">INTERIM</status_change>
            <status_change date="2014-10-27T04:01:38.324-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5413" test_ref="oval:org.mitre.oval:tst:123102"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21408" test_ref="oval:org.mitre.oval:tst:123204"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista/2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19165" test_ref="oval:org.mitre.oval:tst:123599"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23470" test_ref="oval:org.mitre.oval:tst:123011"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23619" test_ref="oval:org.mitre.oval:tst:123007"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19561" test_ref="oval:org.mitre.oval:tst:123464"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23619" test_ref="oval:org.mitre.oval:tst:123007"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18571" test_ref="oval:org.mitre.oval:tst:123348"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22777" test_ref="oval:org.mitre.oval:tst:123326"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16575" test_ref="oval:org.mitre.oval:tst:122615"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20691" test_ref="oval:org.mitre.oval:tst:123605"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17088" test_ref="oval:org.mitre.oval:tst:123567"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21207" test_ref="oval:org.mitre.oval:tst:123452"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7, 2k8 r2, win 8 or 2k12 r2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vuln file version">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17280" test_ref="oval:org.mitre.oval:tst:123331"/>
            </criteria>
            <criteria operator="AND" comment="Win 8 / 2k12 r2 and vuln file version">
              <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17278" test_ref="oval:org.mitre.oval:tst:123432"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26811" version="3" class="vulnerability">
      <metadata>
        <title>Internet explorer memory corruption vulnerability - CVE-2014-4104 (MS14-052)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-4104" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4104"/>
        <description>Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-2799, CVE-2014-4059, CVE-2014-4065, CVE-2014-4079, CVE-2014-4081, CVE-2014-4083, CVE-2014-4085, CVE-2014-4088, CVE-2014-4090, CVE-2014-4094, CVE-2014-4097, CVE-2014-4100, CVE-2014-4103, CVE-2014-4105, CVE-2014-4106, CVE-2014-4107, CVE-2014-4108, CVE-2014-4109, CVE-2014-4110, and CVE-2014-4111.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-09-12T20:45:43">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-09-17T10:54:36.085-04:00">DRAFT</status_change>
            <status_change date="2014-10-06T04:04:07.096-04:00">INTERIM</status_change>
            <status_change date="2014-10-27T04:01:37.655-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5413" test_ref="oval:org.mitre.oval:tst:123102"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21408" test_ref="oval:org.mitre.oval:tst:123204"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista/2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19165" test_ref="oval:org.mitre.oval:tst:123599"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23470" test_ref="oval:org.mitre.oval:tst:123011"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23619" test_ref="oval:org.mitre.oval:tst:123007"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19561" test_ref="oval:org.mitre.oval:tst:123464"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23619" test_ref="oval:org.mitre.oval:tst:123007"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18571" test_ref="oval:org.mitre.oval:tst:123348"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22777" test_ref="oval:org.mitre.oval:tst:123326"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16575" test_ref="oval:org.mitre.oval:tst:122615"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20691" test_ref="oval:org.mitre.oval:tst:123605"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17088" test_ref="oval:org.mitre.oval:tst:123567"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21207" test_ref="oval:org.mitre.oval:tst:123452"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7, 2k8 r2, win 8 or 2k12 r2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vuln file version">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17280" test_ref="oval:org.mitre.oval:tst:123331"/>
            </criteria>
            <criteria operator="AND" comment="Win 8 / 2k12 r2 and vuln file version">
              <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17278" test_ref="oval:org.mitre.oval:tst:123432"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26798" version="3" class="vulnerability">
      <metadata>
        <title>Internet explorer memory corruption vulnerability - CVE-2014-4105 (MS14-052)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-4105" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4105"/>
        <description>Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-2799, CVE-2014-4059, CVE-2014-4065, CVE-2014-4079, CVE-2014-4081, CVE-2014-4083, CVE-2014-4085, CVE-2014-4088, CVE-2014-4090, CVE-2014-4094, CVE-2014-4097, CVE-2014-4100, CVE-2014-4103, CVE-2014-4104, CVE-2014-4106, CVE-2014-4107, CVE-2014-4108, CVE-2014-4109, CVE-2014-4110, and CVE-2014-4111.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-09-12T20:45:43">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-09-17T10:54:07.380-04:00">DRAFT</status_change>
            <status_change date="2014-10-06T04:04:06.429-04:00">INTERIM</status_change>
            <status_change date="2014-10-27T04:01:36.416-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5413" test_ref="oval:org.mitre.oval:tst:123102"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21408" test_ref="oval:org.mitre.oval:tst:123204"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista/2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19165" test_ref="oval:org.mitre.oval:tst:123599"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23470" test_ref="oval:org.mitre.oval:tst:123011"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23619" test_ref="oval:org.mitre.oval:tst:123007"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19561" test_ref="oval:org.mitre.oval:tst:123464"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23619" test_ref="oval:org.mitre.oval:tst:123007"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18571" test_ref="oval:org.mitre.oval:tst:123348"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22777" test_ref="oval:org.mitre.oval:tst:123326"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16575" test_ref="oval:org.mitre.oval:tst:122615"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20691" test_ref="oval:org.mitre.oval:tst:123605"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17088" test_ref="oval:org.mitre.oval:tst:123567"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21207" test_ref="oval:org.mitre.oval:tst:123452"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7, 2k8 r2, win 8 or 2k12 r2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vuln file version">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17280" test_ref="oval:org.mitre.oval:tst:123331"/>
            </criteria>
            <criteria operator="AND" comment="Win 8 / 2k12 r2 and vuln file version">
              <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17278" test_ref="oval:org.mitre.oval:tst:123432"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26791" version="3" class="vulnerability">
      <metadata>
        <title>Internet explorer memory corruption vulnerability - CVE-2014-4107 (MS14-052)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-4107" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4107"/>
        <description>Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-2799, CVE-2014-4059, CVE-2014-4065, CVE-2014-4079, CVE-2014-4081, CVE-2014-4083, CVE-2014-4085, CVE-2014-4088, CVE-2014-4090, CVE-2014-4094, CVE-2014-4097, CVE-2014-4100, CVE-2014-4103, CVE-2014-4104, CVE-2014-4105, CVE-2014-4106, CVE-2014-4108, CVE-2014-4109, CVE-2014-4110, and CVE-2014-4111.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-09-12T20:45:43">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-09-17T10:54:53.707-04:00">DRAFT</status_change>
            <status_change date="2014-10-06T04:04:05.896-04:00">INTERIM</status_change>
            <status_change date="2014-10-27T04:01:35.606-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5413" test_ref="oval:org.mitre.oval:tst:123102"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21408" test_ref="oval:org.mitre.oval:tst:123204"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista/2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19165" test_ref="oval:org.mitre.oval:tst:123599"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23470" test_ref="oval:org.mitre.oval:tst:123011"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23619" test_ref="oval:org.mitre.oval:tst:123007"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19561" test_ref="oval:org.mitre.oval:tst:123464"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23619" test_ref="oval:org.mitre.oval:tst:123007"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18571" test_ref="oval:org.mitre.oval:tst:123348"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22777" test_ref="oval:org.mitre.oval:tst:123326"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16575" test_ref="oval:org.mitre.oval:tst:122615"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20691" test_ref="oval:org.mitre.oval:tst:123605"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17088" test_ref="oval:org.mitre.oval:tst:123567"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21207" test_ref="oval:org.mitre.oval:tst:123452"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7, 2k8 r2, win 8 or 2k12 r2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vuln file version">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17280" test_ref="oval:org.mitre.oval:tst:123331"/>
            </criteria>
            <criteria operator="AND" comment="Win 8 / 2k12 r2 and vuln file version">
              <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17278" test_ref="oval:org.mitre.oval:tst:123432"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26788" version="3" class="vulnerability">
      <metadata>
        <title>Internet explorer memory corruption vulnerability - CVE-2014-4099 (MS14-052)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-4099" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4099"/>
        <description>Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-09-12T20:45:43">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-09-17T10:54:11.466-04:00">DRAFT</status_change>
            <status_change date="2014-10-06T04:04:05.622-04:00">INTERIM</status_change>
            <status_change date="2014-10-27T04:01:35.229-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16575" test_ref="oval:org.mitre.oval:tst:122615"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20691" test_ref="oval:org.mitre.oval:tst:123605"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17088" test_ref="oval:org.mitre.oval:tst:123567"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21207" test_ref="oval:org.mitre.oval:tst:123452"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7, 2k8 r2, win 8 or 2k12 r2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vuln file version">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17280" test_ref="oval:org.mitre.oval:tst:123331"/>
            </criteria>
            <criteria operator="AND" comment="Win 8 / 2k12 r2 and vuln file version">
              <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17278" test_ref="oval:org.mitre.oval:tst:123432"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26785" version="3" class="vulnerability">
      <metadata>
        <title>Internet explorer memory corruption vulnerability - CVE-2014-4103 (MS14-052)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-4103" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4103"/>
        <description>Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-2799, CVE-2014-4059, CVE-2014-4065, CVE-2014-4079, CVE-2014-4081, CVE-2014-4083, CVE-2014-4085, CVE-2014-4088, CVE-2014-4090, CVE-2014-4094, CVE-2014-4097, CVE-2014-4100, CVE-2014-4104, CVE-2014-4105, CVE-2014-4106, CVE-2014-4107, CVE-2014-4108, CVE-2014-4109, CVE-2014-4110, and CVE-2014-4111.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-09-12T20:45:43">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-09-17T10:55:13.333-04:00">DRAFT</status_change>
            <status_change date="2014-10-06T04:04:05.362-04:00">INTERIM</status_change>
            <status_change date="2014-10-27T04:01:34.769-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5413" test_ref="oval:org.mitre.oval:tst:123102"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21408" test_ref="oval:org.mitre.oval:tst:123204"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista/2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19165" test_ref="oval:org.mitre.oval:tst:123599"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23470" test_ref="oval:org.mitre.oval:tst:123011"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23619" test_ref="oval:org.mitre.oval:tst:123007"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19561" test_ref="oval:org.mitre.oval:tst:123464"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23619" test_ref="oval:org.mitre.oval:tst:123007"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18571" test_ref="oval:org.mitre.oval:tst:123348"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22777" test_ref="oval:org.mitre.oval:tst:123326"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16575" test_ref="oval:org.mitre.oval:tst:122615"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20691" test_ref="oval:org.mitre.oval:tst:123605"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17088" test_ref="oval:org.mitre.oval:tst:123567"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21207" test_ref="oval:org.mitre.oval:tst:123452"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7, 2k8 r2, win 8 or 2k12 r2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vuln file version">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17280" test_ref="oval:org.mitre.oval:tst:123331"/>
            </criteria>
            <criteria operator="AND" comment="Win 8 / 2k12 r2 and vuln file version">
              <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17278" test_ref="oval:org.mitre.oval:tst:123432"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26784" version="3" class="vulnerability">
      <metadata>
        <title>Task Scheduler Vulnerability - CVE-2014-4074 (MS14-054)</title>
        <affected family="windows">
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-4074" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4074"/>
        <description>The Task Scheduler in Microsoft Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges via an application that schedules a crafted task, aka "Task Scheduler Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-09-12T08:17:56">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-09-17T10:57:01.325-04:00">DRAFT</status_change>
            <status_change date="2014-10-06T04:04:05.258-04:00">INTERIM</status_change>
            <status_change date="2014-10-27T04:01:34.598-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Win 8 /2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version schedsvc.dll is less than 6.2.9200.17068" test_ref="oval:org.mitre.oval:tst:123505"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of schedsvc.dll is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:123323"/>
              <criterion comment="Check if the version of schedsvc.dll is less than 6.2.9200.21188" test_ref="oval:org.mitre.oval:tst:122894"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1 /2k12 R2 and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of schedsvc.dll is less than 6.3.9600.17276" test_ref="oval:org.mitre.oval:tst:122990"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26757" version="4" class="vulnerability">
      <metadata>
        <title>.NET Framework remote code execution vulnerability  - CVE-2014-4121 (MS14-057)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft .NET Framework 2.0</product>
          <product>Microsoft .NET Framework 3.5.1</product>
          <product>Microsoft .NET Framework 4.0</product>
          <product>Microsoft .NET Framework 4.5</product>
          <product>Microsoft .NET Framework 4.5.1</product>
          <product>Microsoft .NET Framework 4.5.2</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-4121" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4121"/>
        <description>Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, and 4.5.2 does not properly parse internationalized resource identifiers, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted request to a .NET web application, aka ".NET Framework Remote Code Execution Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-10-17T10:59:59">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-10-17T17:45:40.018-04:00">DRAFT</status_change>
            <status_change date="2014-11-03T04:00:16.786-05:00">INTERIM</status_change>
            <status_change date="2014-11-24T04:00:49.183-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:26757 - Changed product names to represent versions consistently." date="2015-08-17T14:52:00.686-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-08-17T14:55:18.326-04:00">INTERIM</status_change>
          </dates>
          <status>INTERIM</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment=".net 2.0 sp2/server 2003/versions">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 2.0 Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6158"/>
          <criteria operator="OR" comment="either file versions GDR/LDR">
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of system.dll is less than 2.0.50727.8637" test_ref="oval:org.mitre.oval:tst:124441"/>
              <criterion comment="Check if the version of system.dll is greater than or equal to 2.0.50727.8600" test_ref="oval:org.mitre.oval:tst:124979"/>
            </criteria>
            <criterion comment="Check if the version of system.dll is less than 2.0.50727.3662" test_ref="oval:org.mitre.oval:tst:124945"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Vista / 2k8 + vulnerable file version">
          <criteria operator="OR" comment="Vista / 2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="either file versions">
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of system.dl is less than 2.0.50727.7071" test_ref="oval:org.mitre.oval:tst:124941"/>
              <criterion comment="Check if the version of System.dll is greater than or equal to 2.0.50727.7000" test_ref="oval:org.mitre.oval:tst:125120"/>
            </criteria>
            <criterion comment="Check if the version of system.dll is less than 2.0.50727.4253" test_ref="oval:org.mitre.oval:tst:125045"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 2.0 Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6158"/>
        </criteria>
        <criteria operator="AND" comment="Win 8/2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="either file versions">
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of system.dl is less than 2.0.50727.7071" test_ref="oval:org.mitre.oval:tst:124941"/>
              <criterion comment="Check if the version of System.dll is greater than or equal to 2.0.50727.7000" test_ref="oval:org.mitre.oval:tst:125120"/>
            </criteria>
            <criterion comment="Check if the version of the system.dll is less than 2.0.50727.6421" test_ref="oval:org.mitre.oval:tst:125243"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 3.5 SP1 is installed" definition_ref="oval:org.mitre.oval:def:12542"/>
        </criteria>
        <criteria operator="AND" comment=".net 3.5.1/win 8.1/server 2012 r2/versions">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 3.5 SP1 is installed" definition_ref="oval:org.mitre.oval:def:12542"/>
          <criteria operator="OR" comment="either file versions">
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of system.dll is less than 2.0.50727.8615" test_ref="oval:org.mitre.oval:tst:124983"/>
              <criterion comment="Check if the version of system.dll is greater than or equal to 2.0.50727.8600" test_ref="oval:org.mitre.oval:tst:124979"/>
            </criteria>
            <criterion comment="Check if the version of system.dll is less than 2.0.50727.8009" test_ref="oval:org.mitre.oval:tst:125152"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / R2 + vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
          </criteria>
          <criteria operator="OR" comment="either file versions">
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of system.dl is less than 2.0.50727.7071" test_ref="oval:org.mitre.oval:tst:124941"/>
              <criterion comment="Check if the version of System.dll is greater than or equal to 2.0.50727.7000" test_ref="oval:org.mitre.oval:tst:125120"/>
            </criteria>
            <criterion comment="Check if the version of system.dll is less than 2.0.50727.5485" test_ref="oval:org.mitre.oval:tst:125005"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 3.5 SP1 is installed" definition_ref="oval:org.mitre.oval:def:12542"/>
        </criteria>
        <criteria operator="AND" comment=".net 4.0/win server 2003/vista/server 2008/Win 7/ server 2008 R2 and vuln versions">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6749"/>
          <criteria operator="OR" comment="GDR/LDR">
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of system.dll is less than 4.0.30319.2045" test_ref="oval:org.mitre.oval:tst:125168"/>
              <criterion comment="Check if the version of system.dl is greater than or equal to 4.0.30319.2000" test_ref="oval:org.mitre.oval:tst:125128"/>
            </criteria>
            <criterion comment="Check if the version of system.dll is less than 4.0.30319.1026" test_ref="oval:org.mitre.oval:tst:125066"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment=".net 4.5/4.5.1/4.5.2/vista/server 2008/win 7/server 2008 R2/versions">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="4.5/4.5.1/4.5.2">
            <extend_definition comment="Microsoft .NET Framework 4.5 is installed" definition_ref="oval:org.mitre.oval:def:15925"/>
            <extend_definition comment="Microsoft .NET Framework 4.5.1 is installed" definition_ref="oval:org.mitre.oval:def:22275"/>
            <extend_definition comment="Microsoft .NET Framework 4.5.2 is installed" definition_ref="oval:org.mitre.oval:def:26546"/>
          </criteria>
          <criteria operator="OR" comment="LDR / GDR range">
            <criteria operator="AND" comment="LDR range">
              <criterion comment="Check if the version of system.dll is less than 4.0.30319.36250" test_ref="oval:org.mitre.oval:tst:125169"/>
              <criterion comment="Check if the version of system.dll is greater than or equal to 4.0.30319.36000" test_ref="oval:org.mitre.oval:tst:124981"/>
            </criteria>
            <criterion comment="Check if the version of system.dll is less than 4.0.30319.34238" test_ref="oval:org.mitre.oval:tst:125064"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1/2k12 R2 and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criteria operator="OR" comment="4.5.1/4.5.2">
            <extend_definition comment="Microsoft .NET Framework 4.5.1 is installed" definition_ref="oval:org.mitre.oval:def:22275"/>
            <extend_definition comment="Microsoft .NET Framework 4.5.2 is installed" definition_ref="oval:org.mitre.oval:def:26546"/>
          </criteria>
          <criteria operator="OR" comment="either file versions">
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of system.dll is less than 4.0.30319.36251" test_ref="oval:org.mitre.oval:tst:125056"/>
              <criterion comment="Check if the version of system.dll is greater than or equal to 4.0.30319.36000" test_ref="oval:org.mitre.oval:tst:124981"/>
            </criteria>
            <criterion comment="Check if the version of system.dll is less than 4.0.30319.34239" test_ref="oval:org.mitre.oval:tst:125032"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment=".net 4.5/4.5.1/4.5.2/win 8/server 2012/versions">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="4.5/4.5.1/4.5.2">
            <extend_definition comment="Microsoft .NET Framework 4.5 is installed" definition_ref="oval:org.mitre.oval:def:15925"/>
            <extend_definition comment="Microsoft .NET Framework 4.5.1 is installed" definition_ref="oval:org.mitre.oval:def:22275"/>
            <extend_definition comment="Microsoft .NET Framework 4.5.2 is installed" definition_ref="oval:org.mitre.oval:def:26546"/>
          </criteria>
          <criteria operator="OR" comment="either file versions">
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of system.dll is less than 4.0.30319.36251" test_ref="oval:org.mitre.oval:tst:125056"/>
              <criterion comment="Check if the version of system.dll is greater than or equal to 4.0.30319.36000" test_ref="oval:org.mitre.oval:tst:124981"/>
            </criteria>
            <criterion comment="Check if the version of system.dll is less than 4.0.30319.34239" test_ref="oval:org.mitre.oval:tst:125032"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26746" version="3" class="vulnerability">
      <metadata>
        <title>Alows man-in-the-middle attackers to spoof servers and read encrypted domain credentials via a crafted certificate</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2013-3876" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3876"/>
        <description>DirectAccess in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 does not properly verify server X.509 certificates, which allows man-in-the-middle attackers to spoof servers and read encrypted domain credentials via a crafted certificate.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-09-03T08:31:03">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </submitted>
            <status_change date="2014-09-19T15:06:07.129-04:00">DRAFT</status_change>
            <status_change date="2014-10-06T04:04:03.860-04:00">INTERIM</status_change>
            <status_change date="2014-10-27T04:01:30.262-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Oakley.dll and XP">
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <criterion comment="Check if the version of Oakley.dll is less than 5.1.2600.6462" test_ref="oval:org.mitre.oval:tst:123290"/>
        </criteria>
        <criteria operator="AND" comment="Oakley.dll and XP or 2003">
          <criteria operator="OR" comment="OS">
            <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
          </criteria>
          <criterion comment="Check if the version of Oakley.dll is less than 5.2.3790.5238" test_ref="oval:org.mitre.oval:tst:123609"/>
        </criteria>
        <criteria operator="AND" comment="Ikeext.dll and Vista or 2008">
          <criteria operator="OR" comment="OS">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:4873"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
            <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of Ikeext.dll is less than 6.0.6002.18960" test_ref="oval:org.mitre.oval:tst:122774"/>
            <criteria operator="AND" comment="ldr">
              <criterion comment="Check if the version of Ikeext.dll is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:123713"/>
              <criterion comment="Check if the version of Ikeext.dll is less than 6.0.6002.23243" test_ref="oval:org.mitre.oval:tst:123737"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Ikeext.dll and 7 or 2008R2">
          <criteria operator="OR" comment="OS">
            <extend_definition comment="Microsoft Windows 7 (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12292"/>
            <extend_definition comment="Microsoft Windows 7 x64 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12627"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12583"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12567"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of Ikeext.dll is less than 6.1.7601.18283" test_ref="oval:org.mitre.oval:tst:123545"/>
            <criteria operator="AND" comment="ldr">
              <criterion comment="Check if the version of Ikeext.dll is less than 6.1.7601.22479" test_ref="oval:org.mitre.oval:tst:123653"/>
              <criterion comment="Check if the version of Ikeext.dll is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:123216"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Ikeext.dll and 8 or 2012">
          <criteria operator="OR" comment="OS">
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows Server 2012 is installed" definition_ref="oval:org.mitre.oval:def:16359"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of Ikeext.dll is less than 6.2.9200.16734" test_ref="oval:org.mitre.oval:tst:123603"/>
            <criteria operator="AND" comment="ldr">
              <criterion comment="Check if the version of Ikeext.dll is greater than or equal to 6.2.9200.20000" test_ref="oval:org.mitre.oval:tst:123707"/>
              <criterion comment="Check if the version of Ikeext.dll is less than 6.2.9200.20846" test_ref="oval:org.mitre.oval:tst:123157"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Ikeext.dll and 8.1 or 2012R2">
          <criteria operator="OR" comment="OS">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of Ikeext.dll is less than 6.3.9600.16427" test_ref="oval:org.mitre.oval:tst:123120"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:4873" version="6" class="inventory">
      <metadata>
        <title>Microsoft Windows Vista (32-bit) Service Pack 1 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/o:microsoft:windows_vista::sp1:x86"/>
        <description>The operating system installed on the system is Microsoft Windows Vista (32-bit) Service Pack 1</description>
        <oval_repository>
          <dates>
            <submitted date="2008-03-26T10:44:02">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </submitted>
            <status_change date="2008-03-26T16:27:29.495-04:00">DRAFT</status_change>
            <modified comment="Changed the CPE reference" date="2008-04-04T11:17:00.108-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2008-04-21T04:00:20.428-04:00">INTERIM</status_change>
            <status_change date="2008-05-12T04:00:14.497-04:00">ACCEPTED</status_change>
            <modified comment="Replaced negation of test for x64 with a case insensitive test for x86 and changed the tests for SP1, Vista, and windows to be case insensitive" date="2009-12-02T16:05:00.749-04:00">
              <contributor organization="National Institute of Standards and Technology">Tim Harrison</contributor>
            </modified>
            <status_change date="2009-12-02T16:05:00.749-04:00">INTERIM</status_change>
            <modified comment="Added anchors and spaces to regular expression" date="2009-12-04T14:55:00.401-05:00">
              <contributor organization="National Institute of Standards and Technology">Tim Harrison</contributor>
            </modified>
            <modified comment="Updating regex to include parenthesis" date="2009-12-08T17:31:00.669-05:00">
              <contributor organization="National Institute of Standards and Technology">Tim Harrison</contributor>
            </modified>
            <status_change date="2010-01-04T04:01:34.223-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2011-04-25T14:45:45.918-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:03:06.709-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="the installed operating system is part of the Microsoft Windows family" test_ref="oval:org.mitre.oval:tst:99"/>
        <criterion comment="Windows Vista is installed" test_ref="oval:org.mitre.oval:tst:7914"/>
        <criterion comment="a version of Windows for the x86 architecture is installed" test_ref="oval:org.mitre.oval:tst:3823"/>
        <criterion comment="Win2K/XP/2003/Vista service pack 1 is installed" test_ref="oval:org.mitre.oval:tst:2843"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26733" version="3" class="vulnerability">
      <metadata>
        <title>Internet explorer elevation of privilege vulnerability - CVE-2014-4124 (MS14-056)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-4124" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4124"/>
        <description>Microsoft Internet Explorer 7 through 11 allows remote attackers to gain privileges via a crafted web site, aka "Internet Explorer Elevation of Privilege Vulnerability," a different vulnerability than CVE-2014-4123.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-10-17T20:45:43">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-10-17T17:28:40.127-04:00">DRAFT</status_change>
            <status_change date="2014-11-03T04:00:15.863-05:00">INTERIM</status_change>
            <status_change date="2014-11-24T04:00:46.649-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21409" test_ref="oval:org.mitre.oval:tst:125221"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista/2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19185" test_ref="oval:org.mitre.oval:tst:124464"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23489" test_ref="oval:org.mitre.oval:tst:125174"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23627" test_ref="oval:org.mitre.oval:tst:124999"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19569" test_ref="oval:org.mitre.oval:tst:125163"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23627" test_ref="oval:org.mitre.oval:tst:124999"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18595" test_ref="oval:org.mitre.oval:tst:124250"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22803" test_ref="oval:org.mitre.oval:tst:125113"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16584" test_ref="oval:org.mitre.oval:tst:125036"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20700" test_ref="oval:org.mitre.oval:tst:125029"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17116" test_ref="oval:org.mitre.oval:tst:125116"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21232" test_ref="oval:org.mitre.oval:tst:124505"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7 / 2k8 R2/8.1/2012 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17344" test_ref="oval:org.mitre.oval:tst:125090"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26726" version="3" class="vulnerability">
      <metadata>
        <title>Internet explorer memory corruption vulnerability - CVE-2014-4092 (MS14-052)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-4092" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4092"/>
        <description>Microsoft Internet Explorer 8 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-4098.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-09-12T20:45:43">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-09-17T10:54:09.687-04:00">DRAFT</status_change>
            <status_change date="2014-10-06T04:04:02.645-04:00">INTERIM</status_change>
            <status_change date="2014-10-27T04:01:28.340-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23619" test_ref="oval:org.mitre.oval:tst:123007"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19561" test_ref="oval:org.mitre.oval:tst:123464"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23619" test_ref="oval:org.mitre.oval:tst:123007"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18571" test_ref="oval:org.mitre.oval:tst:123348"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22777" test_ref="oval:org.mitre.oval:tst:123326"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16575" test_ref="oval:org.mitre.oval:tst:122615"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20691" test_ref="oval:org.mitre.oval:tst:123605"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17088" test_ref="oval:org.mitre.oval:tst:123567"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21207" test_ref="oval:org.mitre.oval:tst:123452"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7, 2k8 r2, win 8 or 2k12 r2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vuln file version">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17280" test_ref="oval:org.mitre.oval:tst:123331"/>
            </criteria>
            <criteria operator="AND" comment="Win 8 / 2k12 r2 and vuln file version">
              <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17278" test_ref="oval:org.mitre.oval:tst:123432"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26693" version="3" class="vulnerability">
      <metadata>
        <title>Internet explorer memory corruption vulnerability - CVE-2014-4089 (MS14-052)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-4089" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4089"/>
        <description>Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-4080, CVE-2014-4091, and CVE-2014-4102.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-09-12T20:45:43">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-09-17T10:54:43.809-04:00">DRAFT</status_change>
            <status_change date="2014-10-06T04:03:59.575-04:00">INTERIM</status_change>
            <status_change date="2014-10-27T04:01:24.753-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17088" test_ref="oval:org.mitre.oval:tst:123567"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21207" test_ref="oval:org.mitre.oval:tst:123452"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7, 2k8 r2, win 8 or 2k12 r2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vuln file version">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17280" test_ref="oval:org.mitre.oval:tst:123331"/>
            </criteria>
            <criteria operator="AND" comment="Win 8 / 2k12 r2 and vuln file version">
              <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17278" test_ref="oval:org.mitre.oval:tst:123432"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26683" version="3" class="vulnerability">
      <metadata>
        <title>Internet explorer memory corruption vulnerability - CVE-2014-4111 (MS14-052)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-4111" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4111"/>
        <description>Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-2799, CVE-2014-4059, CVE-2014-4065, CVE-2014-4079, CVE-2014-4081, CVE-2014-4083, CVE-2014-4085, CVE-2014-4088, CVE-2014-4090, CVE-2014-4094, CVE-2014-4097, CVE-2014-4100, CVE-2014-4103, CVE-2014-4104, CVE-2014-4105, CVE-2014-4106, CVE-2014-4107, CVE-2014-4108, CVE-2014-4109, and CVE-2014-4110.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-09-12T20:45:43">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-09-17T10:54:59.525-04:00">DRAFT</status_change>
            <status_change date="2014-10-06T04:03:58.412-04:00">INTERIM</status_change>
            <status_change date="2014-10-27T04:01:23.038-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5413" test_ref="oval:org.mitre.oval:tst:123102"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21408" test_ref="oval:org.mitre.oval:tst:123204"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista/2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19165" test_ref="oval:org.mitre.oval:tst:123599"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23470" test_ref="oval:org.mitre.oval:tst:123011"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23619" test_ref="oval:org.mitre.oval:tst:123007"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19561" test_ref="oval:org.mitre.oval:tst:123464"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23619" test_ref="oval:org.mitre.oval:tst:123007"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18571" test_ref="oval:org.mitre.oval:tst:123348"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22777" test_ref="oval:org.mitre.oval:tst:123326"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16575" test_ref="oval:org.mitre.oval:tst:122615"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20691" test_ref="oval:org.mitre.oval:tst:123605"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17088" test_ref="oval:org.mitre.oval:tst:123567"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21207" test_ref="oval:org.mitre.oval:tst:123452"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7, 2k8 r2, win 8 or 2k12 r2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vuln file version">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17280" test_ref="oval:org.mitre.oval:tst:123331"/>
            </criteria>
            <criteria operator="AND" comment="Win 8 / 2k12 r2 and vuln file version">
              <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17278" test_ref="oval:org.mitre.oval:tst:123432"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26682" version="3" class="vulnerability">
      <metadata>
        <title>Internet explorer memory corruption vulnerability - CVE-2014-4106 (MS14-052)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-4106" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4106"/>
        <description>Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-2799, CVE-2014-4059, CVE-2014-4065, CVE-2014-4079, CVE-2014-4081, CVE-2014-4083, CVE-2014-4085, CVE-2014-4088, CVE-2014-4090, CVE-2014-4094, CVE-2014-4097, CVE-2014-4100, CVE-2014-4103, CVE-2014-4104, CVE-2014-4105, CVE-2014-4107, CVE-2014-4108, CVE-2014-4109, CVE-2014-4110, and CVE-2014-4111.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-09-12T20:45:43">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-09-17T10:54:56.660-04:00">DRAFT</status_change>
            <status_change date="2014-10-06T04:03:58.206-04:00">INTERIM</status_change>
            <status_change date="2014-10-27T04:01:22.517-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5413" test_ref="oval:org.mitre.oval:tst:123102"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21408" test_ref="oval:org.mitre.oval:tst:123204"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista/2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19165" test_ref="oval:org.mitre.oval:tst:123599"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23470" test_ref="oval:org.mitre.oval:tst:123011"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23619" test_ref="oval:org.mitre.oval:tst:123007"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19561" test_ref="oval:org.mitre.oval:tst:123464"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23619" test_ref="oval:org.mitre.oval:tst:123007"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18571" test_ref="oval:org.mitre.oval:tst:123348"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22777" test_ref="oval:org.mitre.oval:tst:123326"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16575" test_ref="oval:org.mitre.oval:tst:122615"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20691" test_ref="oval:org.mitre.oval:tst:123605"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17088" test_ref="oval:org.mitre.oval:tst:123567"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21207" test_ref="oval:org.mitre.oval:tst:123452"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7, 2k8 r2, win 8 or 2k12 r2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vuln file version">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17280" test_ref="oval:org.mitre.oval:tst:123331"/>
            </criteria>
            <criteria operator="AND" comment="Win 8 / 2k12 r2 and vuln file version">
              <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17278" test_ref="oval:org.mitre.oval:tst:123432"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26680" version="3" class="vulnerability">
      <metadata>
        <title>Lync Denial of Service vulnerability (CVE-2014-4068) - MS14-055</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Lync Server 2013</product>
          <product>Microsoft Lync Server 2010</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-4068" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4068"/>
        <description>The Response Group Service in Microsoft Lync Server 2010 and 2013 and the Core Components in Lync Server 2013 do not properly handle exceptions, which allows remote attackers to cause a denial of service (daemon hang) via a crafted call, aka "Lync Denial of Service Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-09-12T17:08:37">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-09-17T10:58:56.842-04:00">DRAFT</status_change>
            <status_change date="2014-10-06T04:03:58.073-04:00">INTERIM</status_change>
            <status_change date="2014-10-27T04:01:22.329-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Lync server 2013 / vulnerable file version">
          <extend_definition comment="Microsoft Lync Server 2013 is installed" definition_ref="oval:org.mitre.oval:def:16524"/>
          <criteria operator="OR" comment="either file versions">
            <criterion comment="Check if the version of Microsoft.Rtc.Acd.Workflow.dll is less than 5.0.8308.803" test_ref="oval:org.mitre.oval:tst:123294"/>
            <criterion comment="Check if the version of Deploy.resources.dll is less than 5.0.8308.420" test_ref="oval:org.mitre.oval:tst:123329"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Lync server 2010 / vulnerable file version">
          <extend_definition comment="Microsoft Lync Server 2010 is installed" definition_ref="oval:org.mitre.oval:def:26794"/>
          <criteria operator="OR" comment="either file versions">
            <criterion comment="Check if the version of wrtces.dll is less than 4.0.7577.230" test_ref="oval:org.mitre.oval:tst:123304"/>
            <criterion comment="Check if the version of Microsoft.Rtc.Acd.Workflow.dll is less than 4.0.7577.276" test_ref="oval:org.mitre.oval:tst:122801"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26677" version="3" class="vulnerability">
      <metadata>
        <title>Internet explorer memory corruption vulnerability - CVE-2014-4098 (MS14-052)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-4098" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4098"/>
        <description>Microsoft Internet Explorer 8 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-4092.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-09-12T20:45:43">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-09-17T10:55:04.777-04:00">DRAFT</status_change>
            <status_change date="2014-10-06T04:03:57.299-04:00">INTERIM</status_change>
            <status_change date="2014-10-27T04:01:21.511-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23619" test_ref="oval:org.mitre.oval:tst:123007"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19561" test_ref="oval:org.mitre.oval:tst:123464"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23619" test_ref="oval:org.mitre.oval:tst:123007"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18571" test_ref="oval:org.mitre.oval:tst:123348"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22777" test_ref="oval:org.mitre.oval:tst:123326"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16575" test_ref="oval:org.mitre.oval:tst:122615"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20691" test_ref="oval:org.mitre.oval:tst:123605"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17088" test_ref="oval:org.mitre.oval:tst:123567"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21207" test_ref="oval:org.mitre.oval:tst:123452"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7, 2k8 r2, win 8 or 2k12 r2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vuln file version">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17280" test_ref="oval:org.mitre.oval:tst:123331"/>
            </criteria>
            <criteria operator="AND" comment="Win 8 / 2k12 r2 and vuln file version">
              <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17278" test_ref="oval:org.mitre.oval:tst:123432"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26674" version="3" class="vulnerability">
      <metadata>
        <title>Internet explorer memory corruption vulnerability - CVE-2014-4097 (MS14-052)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-4097" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4097"/>
        <description>Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-2799, CVE-2014-4059, CVE-2014-4065, CVE-2014-4079, CVE-2014-4081, CVE-2014-4083, CVE-2014-4085, CVE-2014-4088, CVE-2014-4090, CVE-2014-4094, CVE-2014-4100, CVE-2014-4103, CVE-2014-4104, CVE-2014-4105, CVE-2014-4106, CVE-2014-4107, CVE-2014-4108, CVE-2014-4109, CVE-2014-4110, and CVE-2014-4111.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-09-12T20:45:43">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-09-17T10:54:27.034-04:00">DRAFT</status_change>
            <status_change date="2014-10-06T04:03:56.856-04:00">INTERIM</status_change>
            <status_change date="2014-10-27T04:01:21.023-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5413" test_ref="oval:org.mitre.oval:tst:123102"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21408" test_ref="oval:org.mitre.oval:tst:123204"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista/2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19165" test_ref="oval:org.mitre.oval:tst:123599"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23470" test_ref="oval:org.mitre.oval:tst:123011"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23619" test_ref="oval:org.mitre.oval:tst:123007"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19561" test_ref="oval:org.mitre.oval:tst:123464"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23619" test_ref="oval:org.mitre.oval:tst:123007"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18571" test_ref="oval:org.mitre.oval:tst:123348"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22777" test_ref="oval:org.mitre.oval:tst:123326"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16575" test_ref="oval:org.mitre.oval:tst:122615"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20691" test_ref="oval:org.mitre.oval:tst:123605"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17088" test_ref="oval:org.mitre.oval:tst:123567"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21207" test_ref="oval:org.mitre.oval:tst:123452"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7, 2k8 r2, win 8 or 2k12 r2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vuln file version">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17280" test_ref="oval:org.mitre.oval:tst:123331"/>
            </criteria>
            <criteria operator="AND" comment="Win 8 / 2k12 r2 and vuln file version">
              <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17278" test_ref="oval:org.mitre.oval:tst:123432"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26669" version="3" class="vulnerability">
      <metadata>
        <title>Internet explorer memory corruption vulnerability - CVE-2014-4090 (MS14-052)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-4090" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4090"/>
        <description>Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-2799, CVE-2014-4059, CVE-2014-4065, CVE-2014-4079, CVE-2014-4081, CVE-2014-4083, CVE-2014-4085, CVE-2014-4088, CVE-2014-4094, CVE-2014-4097, CVE-2014-4100, CVE-2014-4103, CVE-2014-4104, CVE-2014-4105, CVE-2014-4106, CVE-2014-4107, CVE-2014-4108, CVE-2014-4109, CVE-2014-4110, and CVE-2014-4111.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-09-12T20:45:43">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-09-17T10:53:53.722-04:00">DRAFT</status_change>
            <status_change date="2014-10-06T04:03:56.070-04:00">INTERIM</status_change>
            <status_change date="2014-10-27T04:01:20.186-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5413" test_ref="oval:org.mitre.oval:tst:123102"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21408" test_ref="oval:org.mitre.oval:tst:123204"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista/2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19165" test_ref="oval:org.mitre.oval:tst:123599"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23470" test_ref="oval:org.mitre.oval:tst:123011"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23619" test_ref="oval:org.mitre.oval:tst:123007"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19561" test_ref="oval:org.mitre.oval:tst:123464"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23619" test_ref="oval:org.mitre.oval:tst:123007"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18571" test_ref="oval:org.mitre.oval:tst:123348"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22777" test_ref="oval:org.mitre.oval:tst:123326"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16575" test_ref="oval:org.mitre.oval:tst:122615"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20691" test_ref="oval:org.mitre.oval:tst:123605"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17088" test_ref="oval:org.mitre.oval:tst:123567"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21207" test_ref="oval:org.mitre.oval:tst:123452"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7, 2k8 r2, win 8 or 2k12 r2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vuln file version">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17280" test_ref="oval:org.mitre.oval:tst:123331"/>
            </criteria>
            <criteria operator="AND" comment="Win 8 / 2k12 r2 and vuln file version">
              <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17278" test_ref="oval:org.mitre.oval:tst:123432"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26664" version="3" class="vulnerability">
      <metadata>
        <title>Internet explorer elevation of privilege vulnerability - CVE-2014-4123 (MS14-056)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-4123" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4123"/>
        <description>Microsoft Internet Explorer 7 through 11 allows remote attackers to gain privileges via a crafted web site, aka "Internet Explorer Elevation of Privilege Vulnerability," as exploited in the wild in October 2014, a different vulnerability than CVE-2014-4124.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-10-17T20:45:43">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-10-17T17:28:58.383-04:00">DRAFT</status_change>
            <status_change date="2014-11-03T04:00:14.671-05:00">INTERIM</status_change>
            <status_change date="2014-11-24T04:00:40.683-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21409" test_ref="oval:org.mitre.oval:tst:125221"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista/2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19185" test_ref="oval:org.mitre.oval:tst:124464"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23489" test_ref="oval:org.mitre.oval:tst:125174"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23627" test_ref="oval:org.mitre.oval:tst:124999"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19569" test_ref="oval:org.mitre.oval:tst:125163"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23627" test_ref="oval:org.mitre.oval:tst:124999"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18595" test_ref="oval:org.mitre.oval:tst:124250"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22803" test_ref="oval:org.mitre.oval:tst:125113"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16584" test_ref="oval:org.mitre.oval:tst:125036"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20700" test_ref="oval:org.mitre.oval:tst:125029"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17116" test_ref="oval:org.mitre.oval:tst:125116"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21232" test_ref="oval:org.mitre.oval:tst:124505"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7 / 2k8 R2/8.1/2012 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17344" test_ref="oval:org.mitre.oval:tst:125090"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26663" version="3" class="vulnerability">
      <metadata>
        <title>Internet explorer memory corruption vulnerability - CVE-2014-4100 (MS14-052)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-4100" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4100"/>
        <description>Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-2799, CVE-2014-4059, CVE-2014-4065, CVE-2014-4079, CVE-2014-4081, CVE-2014-4083, CVE-2014-4085, CVE-2014-4088, CVE-2014-4090, CVE-2014-4094, CVE-2014-4097, CVE-2014-4103, CVE-2014-4104, CVE-2014-4105, CVE-2014-4106, CVE-2014-4107, CVE-2014-4108, CVE-2014-4109, CVE-2014-4110, and CVE-2014-4111.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-09-12T20:45:43">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-09-17T10:55:02.495-04:00">DRAFT</status_change>
            <status_change date="2014-10-06T04:03:55.290-04:00">INTERIM</status_change>
            <status_change date="2014-10-27T04:01:19.302-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5413" test_ref="oval:org.mitre.oval:tst:123102"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21408" test_ref="oval:org.mitre.oval:tst:123204"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista/2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19165" test_ref="oval:org.mitre.oval:tst:123599"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23470" test_ref="oval:org.mitre.oval:tst:123011"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23619" test_ref="oval:org.mitre.oval:tst:123007"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19561" test_ref="oval:org.mitre.oval:tst:123464"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23619" test_ref="oval:org.mitre.oval:tst:123007"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18571" test_ref="oval:org.mitre.oval:tst:123348"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22777" test_ref="oval:org.mitre.oval:tst:123326"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16575" test_ref="oval:org.mitre.oval:tst:122615"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20691" test_ref="oval:org.mitre.oval:tst:123605"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17088" test_ref="oval:org.mitre.oval:tst:123567"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21207" test_ref="oval:org.mitre.oval:tst:123452"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7, 2k8 r2, win 8 or 2k12 r2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vuln file version">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17280" test_ref="oval:org.mitre.oval:tst:123331"/>
            </criteria>
            <criteria operator="AND" comment="Win 8 / 2k12 r2 and vuln file version">
              <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17278" test_ref="oval:org.mitre.oval:tst:123432"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26651" version="3" class="vulnerability">
      <metadata>
        <title>Internet explorer memory corruption vulnerability - CVE-2014-2799 (MS14-052)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-2799" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2799"/>
        <description>Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-4059, CVE-2014-4065, CVE-2014-4079, CVE-2014-4081, CVE-2014-4083, CVE-2014-4085, CVE-2014-4088, CVE-2014-4090, CVE-2014-4094, CVE-2014-4097, CVE-2014-4100, CVE-2014-4103, CVE-2014-4104, CVE-2014-4105, CVE-2014-4106, CVE-2014-4107, CVE-2014-4108, CVE-2014-4109, CVE-2014-4110, and CVE-2014-4111.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-09-12T20:45:43">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-09-17T10:53:56.380-04:00">DRAFT</status_change>
            <status_change date="2014-10-06T04:03:54.508-04:00">INTERIM</status_change>
            <status_change date="2014-10-27T04:01:18.262-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5413" test_ref="oval:org.mitre.oval:tst:123102"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21408" test_ref="oval:org.mitre.oval:tst:123204"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista/2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19165" test_ref="oval:org.mitre.oval:tst:123599"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23470" test_ref="oval:org.mitre.oval:tst:123011"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23619" test_ref="oval:org.mitre.oval:tst:123007"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19561" test_ref="oval:org.mitre.oval:tst:123464"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23619" test_ref="oval:org.mitre.oval:tst:123007"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18571" test_ref="oval:org.mitre.oval:tst:123348"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22777" test_ref="oval:org.mitre.oval:tst:123326"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16575" test_ref="oval:org.mitre.oval:tst:122615"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20691" test_ref="oval:org.mitre.oval:tst:123605"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17088" test_ref="oval:org.mitre.oval:tst:123567"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21207" test_ref="oval:org.mitre.oval:tst:123452"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7, 2k8 r2, win 8 or 2k12 r2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vuln file version">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17280" test_ref="oval:org.mitre.oval:tst:123331"/>
            </criteria>
            <criteria operator="AND" comment="Win 8 / 2k12 r2 and vuln file version">
              <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17278" test_ref="oval:org.mitre.oval:tst:123432"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26645" version="3" class="vulnerability">
      <metadata>
        <title>Internet explorer memory corruption vulnerability - CVE-2014-4059 (MS14-052)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-4059" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4059"/>
        <description>Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-2799, CVE-2014-4065, CVE-2014-4079, CVE-2014-4081, CVE-2014-4083, CVE-2014-4085, CVE-2014-4088, CVE-2014-4090, CVE-2014-4094, CVE-2014-4097, CVE-2014-4100, CVE-2014-4103, CVE-2014-4104, CVE-2014-4105, CVE-2014-4106, CVE-2014-4107, CVE-2014-4108, CVE-2014-4109, CVE-2014-4110, and CVE-2014-4111.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-09-12T20:45:43">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-09-17T10:55:10.493-04:00">DRAFT</status_change>
            <status_change date="2014-10-06T04:03:53.892-04:00">INTERIM</status_change>
            <status_change date="2014-10-27T04:01:17.173-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5413" test_ref="oval:org.mitre.oval:tst:123102"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21408" test_ref="oval:org.mitre.oval:tst:123204"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista/2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19165" test_ref="oval:org.mitre.oval:tst:123599"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23470" test_ref="oval:org.mitre.oval:tst:123011"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23619" test_ref="oval:org.mitre.oval:tst:123007"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19561" test_ref="oval:org.mitre.oval:tst:123464"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23619" test_ref="oval:org.mitre.oval:tst:123007"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18571" test_ref="oval:org.mitre.oval:tst:123348"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22777" test_ref="oval:org.mitre.oval:tst:123326"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16575" test_ref="oval:org.mitre.oval:tst:122615"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20691" test_ref="oval:org.mitre.oval:tst:123605"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17088" test_ref="oval:org.mitre.oval:tst:123567"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21207" test_ref="oval:org.mitre.oval:tst:123452"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7, 2k8 r2, win 8 or 2k12 r2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vuln file version">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17280" test_ref="oval:org.mitre.oval:tst:123331"/>
            </criteria>
            <criteria operator="AND" comment="Win 8 / 2k12 r2 and vuln file version">
              <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17278" test_ref="oval:org.mitre.oval:tst:123432"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26621" version="3" class="vulnerability">
      <metadata>
        <title>Internet explorer memory corruption vulnerability - CVE-2014-4083 (MS14-052)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-4083" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4083"/>
        <description>Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-2799, CVE-2014-4059, CVE-2014-4065, CVE-2014-4079, CVE-2014-4081, CVE-2014-4085, CVE-2014-4088, CVE-2014-4090, CVE-2014-4094, CVE-2014-4097, CVE-2014-4100, CVE-2014-4103, CVE-2014-4104, CVE-2014-4105, CVE-2014-4106, CVE-2014-4107, CVE-2014-4108, CVE-2014-4109, CVE-2014-4110, and CVE-2014-4111.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-09-12T20:45:43">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-09-17T10:54:33.364-04:00">DRAFT</status_change>
            <status_change date="2014-10-06T04:03:51.659-04:00">INTERIM</status_change>
            <status_change date="2014-10-27T04:01:12.785-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5413" test_ref="oval:org.mitre.oval:tst:123102"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21408" test_ref="oval:org.mitre.oval:tst:123204"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista/2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19165" test_ref="oval:org.mitre.oval:tst:123599"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23470" test_ref="oval:org.mitre.oval:tst:123011"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23619" test_ref="oval:org.mitre.oval:tst:123007"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19561" test_ref="oval:org.mitre.oval:tst:123464"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23619" test_ref="oval:org.mitre.oval:tst:123007"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18571" test_ref="oval:org.mitre.oval:tst:123348"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22777" test_ref="oval:org.mitre.oval:tst:123326"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16575" test_ref="oval:org.mitre.oval:tst:122615"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20691" test_ref="oval:org.mitre.oval:tst:123605"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17088" test_ref="oval:org.mitre.oval:tst:123567"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21207" test_ref="oval:org.mitre.oval:tst:123452"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7, 2k8 r2, win 8 or 2k12 r2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vuln file version">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17280" test_ref="oval:org.mitre.oval:tst:123331"/>
            </criteria>
            <criteria operator="AND" comment="Win 8 / 2k12 r2 and vuln file version">
              <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17278" test_ref="oval:org.mitre.oval:tst:123432"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26613" version="3" class="vulnerability">
      <metadata>
        <title>Internet explorer memory corruption vulnerability - CVE-2014-4079 (MS14-052)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-4079" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4079"/>
        <description>Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-2799, CVE-2014-4059, CVE-2014-4065, CVE-2014-4081, CVE-2014-4083, CVE-2014-4085, CVE-2014-4088, CVE-2014-4090, CVE-2014-4094, CVE-2014-4097, CVE-2014-4100, CVE-2014-4103, CVE-2014-4104, CVE-2014-4105, CVE-2014-4106, CVE-2014-4107, CVE-2014-4108, CVE-2014-4109, CVE-2014-4110, and CVE-2014-4111.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-09-12T20:45:43">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-09-17T10:54:39.523-04:00">DRAFT</status_change>
            <status_change date="2014-10-06T04:03:51.145-04:00">INTERIM</status_change>
            <status_change date="2014-10-27T04:01:11.736-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5413" test_ref="oval:org.mitre.oval:tst:123102"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21408" test_ref="oval:org.mitre.oval:tst:123204"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista/2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19165" test_ref="oval:org.mitre.oval:tst:123599"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23470" test_ref="oval:org.mitre.oval:tst:123011"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23619" test_ref="oval:org.mitre.oval:tst:123007"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19561" test_ref="oval:org.mitre.oval:tst:123464"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23619" test_ref="oval:org.mitre.oval:tst:123007"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18571" test_ref="oval:org.mitre.oval:tst:123348"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22777" test_ref="oval:org.mitre.oval:tst:123326"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16575" test_ref="oval:org.mitre.oval:tst:122615"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20691" test_ref="oval:org.mitre.oval:tst:123605"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17088" test_ref="oval:org.mitre.oval:tst:123567"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21207" test_ref="oval:org.mitre.oval:tst:123452"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7, 2k8 r2, win 8 or 2k12 r2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vuln file version">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17280" test_ref="oval:org.mitre.oval:tst:123331"/>
            </criteria>
            <criteria operator="AND" comment="Win 8 / 2k12 r2 and vuln file version">
              <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17278" test_ref="oval:org.mitre.oval:tst:123432"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26611" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer resource information disclosure vulnerability - CVE-2013-7331 (MS14-052)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2013-7331" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-7331"/>
        <description>The Microsoft.XMLDOM ActiveX control in Microsoft Windows 8.1 and earlier allows remote attackers to determine the existence of local pathnames, UNC share pathnames, intranet hostnames, and intranet IP addresses by examining error codes, as demonstrated by a res:// URL, and exploited in the wild in February 2014.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-09-12T20:45:43">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-09-17T10:54:17.303-04:00">DRAFT</status_change>
            <status_change date="2014-10-06T04:03:50.792-04:00">INTERIM</status_change>
            <status_change date="2014-10-27T04:01:11.176-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5413" test_ref="oval:org.mitre.oval:tst:123102"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21408" test_ref="oval:org.mitre.oval:tst:123204"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista/2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19165" test_ref="oval:org.mitre.oval:tst:123599"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23470" test_ref="oval:org.mitre.oval:tst:123011"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23619" test_ref="oval:org.mitre.oval:tst:123007"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19561" test_ref="oval:org.mitre.oval:tst:123464"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23619" test_ref="oval:org.mitre.oval:tst:123007"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18571" test_ref="oval:org.mitre.oval:tst:123348"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22777" test_ref="oval:org.mitre.oval:tst:123326"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16575" test_ref="oval:org.mitre.oval:tst:122615"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20691" test_ref="oval:org.mitre.oval:tst:123605"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17088" test_ref="oval:org.mitre.oval:tst:123567"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21207" test_ref="oval:org.mitre.oval:tst:123452"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7, 2k8 r2, win 8 or 2k12 r2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vuln file version">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17280" test_ref="oval:org.mitre.oval:tst:123331"/>
            </criteria>
            <criteria operator="AND" comment="Win 8 / 2k12 r2 and vuln file version">
              <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17278" test_ref="oval:org.mitre.oval:tst:123432"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26601" version="4" class="vulnerability">
      <metadata>
        <title>.NET framework denial of service vulnerability - CVE-2014-4072 (MS14-053)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft .NET Framework 1.1</product>
          <product>Microsoft .NET Framework 2.0</product>
          <product>Microsoft .NET Framework 3.0</product>
          <product>Microsoft .NET Framework 3.5.1</product>
          <product>Microsoft .NET Framework 4.0</product>
          <product>Microsoft .NET Framework 4.5</product>
          <product>Microsoft .NET Framework 4.5.1</product>
          <product>Microsoft .NET Framework 4.5.2</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-4072" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4072"/>
        <description>Microsoft .NET Framework 1.1 SP1, 2.0 SP2, 3.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, and 4.5.2 does not properly use a hash table for request data, which allows remote attackers to cause a denial of service (resource consumption and ASP.NET performance degradation) via crafted requests, aka ".NET Framework Denial of Service Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-09-12T10:59:59">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-10-15T15:56:34.779-04:00">DRAFT</status_change>
            <status_change date="2014-11-03T04:00:13.105-05:00">INTERIM</status_change>
            <status_change date="2014-11-24T04:00:35.446-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:26601 - Changed product names to represent versions consistently." date="2015-08-17T14:52:00.686-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-08-17T14:55:19.419-04:00">INTERIM</status_change>
          </dates>
          <status>INTERIM</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment=".net 1.1 sp1/versions">
          <criterion comment="Check if the version of mscorlib.dll is less than 1.1.4322.2510" test_ref="oval:org.mitre.oval:tst:124781"/>
          <extend_definition comment="Microsoft .NET Framework 1.1 Service Pack 1 is Installed" definition_ref="oval:org.mitre.oval:def:1834"/>
          <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
        </criteria>
        <criteria operator="AND" comment=".net 2.0 sp2/server 2003/versions">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 2.0 Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6158"/>
          <criteria operator="OR" comment="either file versions GDR/LDR">
            <criterion comment="Check if the version of mscorlib.dll is less than 2.0.50727.3662" test_ref="oval:org.mitre.oval:tst:125038"/>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of mscorlib.dll is less than 2.0.50727.8637" test_ref="oval:org.mitre.oval:tst:124978"/>
              <criterion comment="Check if the version of mscorlib.dll is greater than or equal to 2.0.50727.8600" test_ref="oval:org.mitre.oval:tst:121706"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Vista / 2k8 + vulnerable file version">
          <criteria operator="OR" comment="Vista / 2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="either file versions">
            <criterion comment="Check if the version of mscorlib.dll is less than 2.0.50727.4253" test_ref="oval:org.mitre.oval:tst:124901"/>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of mscorlib.dll is less than 2.0.50727.7071" test_ref="oval:org.mitre.oval:tst:124564"/>
              <criterion comment="Check if the version of mscorlib.dll is greater than or equal to 2.0.50727.7000" test_ref="oval:org.mitre.oval:tst:80994"/>
            </criteria>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 2.0 Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6158"/>
        </criteria>
        <criteria operator="AND" comment=".net 3.0 sp2/server 2003/versions">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 3.0 SP2 is installed" definition_ref="oval:org.mitre.oval:def:15312"/>
          <criterion comment="Check if the version of System.IdentityModel.dll is less than 3.0.4506.4068" test_ref="oval:org.mitre.oval:tst:125058"/>
        </criteria>
        <criteria operator="AND" comment="Vista / 2k8 + vulnerable file version">
          <criteria operator="OR" comment="Vista / 2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="GDR/LDR">
            <criterion comment="Check if the version of system.identitymodel.dll is less than 3.0.4506.4222" test_ref="oval:org.mitre.oval:tst:124817"/>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of System.IdentityModel.dll is less than 3.0.4506.8635" test_ref="oval:org.mitre.oval:tst:125075"/>
              <criterion comment="Check if the version of System.IdentityModel.dll is greater than or equal to 3.0.4506.8600" test_ref="oval:org.mitre.oval:tst:121980"/>
            </criteria>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 3.0 SP2 is installed" definition_ref="oval:org.mitre.oval:def:15312"/>
        </criteria>
        <criteria operator="AND" comment="Win 7 / R2 + vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
          </criteria>
          <criteria operator="OR" comment="either file versions">
            <criterion comment="Check if the version of mscorlib.dll is less than 2.0.50727.5485" test_ref="oval:org.mitre.oval:tst:125118"/>
            <criterion comment="Check if the version of System.IdentityModel.dll is less than 3.0.4506.5463" test_ref="oval:org.mitre.oval:tst:125060"/>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of System.IdentityModel.dll is less than 3.0.4506.8635" test_ref="oval:org.mitre.oval:tst:125075"/>
              <criterion comment="Check if the version of System.IdentityModel.dll is greater than or equal to 3.0.4506.8600" test_ref="oval:org.mitre.oval:tst:121980"/>
            </criteria>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of mscorlib.dll is less than 2.0.50727.7071" test_ref="oval:org.mitre.oval:tst:124564"/>
              <criterion comment="Check if the version of mscorlib.dll is greater than or equal to 2.0.50727.7000" test_ref="oval:org.mitre.oval:tst:80994"/>
            </criteria>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 3.5 SP1 is installed" definition_ref="oval:org.mitre.oval:def:12542"/>
        </criteria>
        <criteria operator="AND" comment="Win 8/2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="either file versions">
            <criterion comment="Check if the version of mscorlib.dll is less than 2.0.50727.6421" test_ref="oval:org.mitre.oval:tst:125017"/>
            <criterion comment="Check if the version of System.IdentityModel.dll is less than 3.0.4506.6415" test_ref="oval:org.mitre.oval:tst:124404"/>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of mscorlib.dll is less than 2.0.50727.7071" test_ref="oval:org.mitre.oval:tst:124564"/>
              <criterion comment="Check if the version of mscorlib.dll is greater than or equal to 2.0.50727.7000" test_ref="oval:org.mitre.oval:tst:80994"/>
            </criteria>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of System.IdentityModel.dll is less than 3.0.4506.8635" test_ref="oval:org.mitre.oval:tst:125075"/>
              <criterion comment="Check if the version of System.IdentityModel.dll is greater than or equal to 3.0.4506.8600" test_ref="oval:org.mitre.oval:tst:121980"/>
            </criteria>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 3.5 SP1 is installed" definition_ref="oval:org.mitre.oval:def:12542"/>
        </criteria>
        <criteria operator="AND" comment=".net 4.0/win server 2003/vista/server 2008/versions">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6749"/>
          <criteria operator="OR" comment="GDR/LDR">
            <criterion comment="Check if the version of mscorlib.dll is less than 4.0.30319.1026" test_ref="oval:org.mitre.oval:tst:125136"/>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of mscorlib.dll is less than 4.0.30319.2045" test_ref="oval:org.mitre.oval:tst:124886"/>
              <criterion comment="Check if the version of mscorlib.dll is greater than or equal to 4.0.30319.2000" test_ref="oval:org.mitre.oval:tst:81701"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment=".net 4.5/4.5.1/4.5.2/vista/server 2008/win 7/server 2008 R2/versions">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="4.5/4.5.1/4.5.2">
            <extend_definition comment="Microsoft .NET Framework 4.5 is installed" definition_ref="oval:org.mitre.oval:def:15925"/>
            <extend_definition comment="Microsoft .NET Framework 4.5.1 is installed" definition_ref="oval:org.mitre.oval:def:22275"/>
            <extend_definition comment="Microsoft .NET Framework 4.5.2 is installed" definition_ref="oval:org.mitre.oval:def:26546"/>
          </criteria>
          <criterion comment="Check if the version of system.identitymodel.dll is less than 4.0.30319.34234" test_ref="oval:org.mitre.oval:tst:125089"/>
        </criteria>
        <criteria operator="AND" comment="Win 8.1/2k12 R2 and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criteria operator="OR" comment="4.5.1/4.5.2">
            <extend_definition comment="Microsoft .NET Framework 4.5.1 is installed" definition_ref="oval:org.mitre.oval:def:22275"/>
            <extend_definition comment="Microsoft .NET Framework 4.5.2 is installed" definition_ref="oval:org.mitre.oval:def:26546"/>
          </criteria>
          <criteria operator="OR" comment="either file versions">
            <criterion comment="Check if the version of system.identitymodel.dll is less than 4.0.30319.34230" test_ref="oval:org.mitre.oval:tst:125134"/>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of system.identitymodel.dll is less than 4.0.30319.36241" test_ref="oval:org.mitre.oval:tst:124665"/>
              <criterion comment="Check if the version of System.IdentityModel.dll is greater than or equal to 4.0.30319.36000" test_ref="oval:org.mitre.oval:tst:124668"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment=".net 4.5/4.5.1/4.5.2/win 8/server 2012/versions">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="4.5/4.5.1/4.5.2">
            <extend_definition comment="Microsoft .NET Framework 4.5 is installed" definition_ref="oval:org.mitre.oval:def:15925"/>
            <extend_definition comment="Microsoft .NET Framework 4.5.1 is installed" definition_ref="oval:org.mitre.oval:def:22275"/>
            <extend_definition comment="Microsoft .NET Framework 4.5.2 is installed" definition_ref="oval:org.mitre.oval:def:26546"/>
          </criteria>
          <criteria operator="OR" comment="either file versions">
            <criterion comment="Check if the version of system.identitymodel.dll is less than 4.0.30319.34230" test_ref="oval:org.mitre.oval:tst:125134"/>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of system.identitymodel.dll is less than 4.0.30319.36241" test_ref="oval:org.mitre.oval:tst:124665"/>
              <criterion comment="Check if the version of System.IdentityModel.dll is greater than or equal to 4.0.30319.36000" test_ref="oval:org.mitre.oval:tst:124668"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment=".net 3.5.1/win 8.1/server 2012 r2/versions">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 3.5 SP1 is installed" definition_ref="oval:org.mitre.oval:def:12542"/>
          <criteria operator="OR" comment="either file versions">
            <criterion comment="Check if the version of System.IdentityModel.dll is less than 3.0.4506.8002" test_ref="oval:org.mitre.oval:tst:124659"/>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of System.IdentityModel.dll is less than 3.0.4506.8635" test_ref="oval:org.mitre.oval:tst:125075"/>
              <criterion comment="Check if the version of System.IdentityModel.dll is greater than or equal to 3.0.4506.8600" test_ref="oval:org.mitre.oval:tst:121980"/>
            </criteria>
            <criterion comment="Check if the version of mscorlib.dll is less than 2.0.50727.8009" test_ref="oval:org.mitre.oval:tst:124916"/>
            <criteria operator="AND" comment="ldr">
              <criterion comment="Check if the version of mscorlib.dll is less than 2.0.50727.8615" test_ref="oval:org.mitre.oval:tst:124861"/>
              <criterion comment="Check if the version of mscorlib.dll is greater than or equal to 2.0.50727.8600" test_ref="oval:org.mitre.oval:tst:121706"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26546" version="4" class="inventory">
      <metadata>
        <title>Microsoft .NET Framework 4.5.2 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows Vista</platform>
          <product>Microsoft .NET Framework 4.5.2</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:.net_framework:4.5:sp2"/>
        <description>Microsoft .NET Framework 4.5.2 is installed</description>
        <oval_repository>
          <dates>
            <submitted date="2014-09-12T11:54:36">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-10-15T15:56:34.014-04:00">DRAFT</status_change>
            <status_change date="2014-11-03T04:00:12.370-05:00">INTERIM</status_change>
            <status_change date="2014-11-24T04:00:30.753-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:26546 - Changed product names to represent versions consistently." date="2015-08-17T14:52:00.686-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-08-17T14:55:18.096-04:00">INTERIM</status_change>
          </dates>
          <status>INTERIM</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="Either release version">
          <criterion comment="Check if the release version of .Net framework 4.5 (client) is equal 379893" test_ref="oval:org.mitre.oval:tst:125079"/>
          <criterion comment="Check if the release version of .Net framework 4.5 (full) is equal to 379893" test_ref="oval:org.mitre.oval:tst:124744"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26594" version="3" class="vulnerability">
      <metadata>
        <title>Internet explorer memory corruption vulnerability - CVE-2014-4080 (MS14-052)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-4080" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4080"/>
        <description>Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-4089, CVE-2014-4091, and CVE-2014-4102.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-09-12T20:45:43">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-09-17T10:53:58.754-04:00">DRAFT</status_change>
            <status_change date="2014-10-06T04:03:49.481-04:00">INTERIM</status_change>
            <status_change date="2014-10-27T04:01:08.967-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17088" test_ref="oval:org.mitre.oval:tst:123567"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21207" test_ref="oval:org.mitre.oval:tst:123452"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7, 2k8 r2, win 8 or 2k12 r2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vuln file version">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17280" test_ref="oval:org.mitre.oval:tst:123331"/>
            </criteria>
            <criteria operator="AND" comment="Win 8 / 2k12 r2 and vuln file version">
              <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17278" test_ref="oval:org.mitre.oval:tst:123432"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26550" version="3" class="vulnerability">
      <metadata>
        <title>Lync Denial of Service vulnerability (CVE-2014-4071) - MS14-055</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Lync Server 2013</product>
          <product>Microsoft Lync Server 2010</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-4071" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4071"/>
        <description>The Server in Microsoft Lync Server 2013 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon hang) via a crafted request, aka "Lync Denial of Service Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-09-12T17:08:37">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-09-17T10:58:56.412-04:00">DRAFT</status_change>
            <status_change date="2014-10-06T04:03:45.038-04:00">INTERIM</status_change>
            <status_change date="2014-10-27T04:01:01.738-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Lync server 2013 / vulnerable file version">
          <extend_definition comment="Microsoft Lync Server 2013 is installed" definition_ref="oval:org.mitre.oval:def:16524"/>
          <criterion comment="Check if the version of SIPStack.dll is less than 5.0.8308.803" test_ref="oval:org.mitre.oval:tst:123219"/>
        </criteria>
        <criteria operator="AND" comment="Lync server 2010 / vulnerable file version">
          <extend_definition comment="Microsoft Lync Server 2010 is installed" definition_ref="oval:org.mitre.oval:def:26794"/>
          <criterion comment="Check if the version of wrtces.dll is less than 4.0.7577.230" test_ref="oval:org.mitre.oval:tst:123304"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26794" version="3" class="inventory">
      <metadata>
        <title>Microsoft Lync Server 2010 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Lync Server 2010</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:lync_server:2010"/>
        <description>Microsoft Lync Server 2010 is installed</description>
        <oval_repository>
          <dates>
            <submitted date="2014-09-12T15:07:42">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-09-17T10:58:55.728-04:00">DRAFT</status_change>
            <status_change date="2014-10-06T04:04:06.363-04:00">INTERIM</status_change>
            <status_change date="2014-10-27T04:01:36.134-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="Check if Microsoft Lync Server 2010 is installed" test_ref="oval:org.mitre.oval:tst:123575"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:16524" version="3" class="inventory">
      <metadata>
        <title>Microsoft Lync Server 2013 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <product>Microsoft Lync Server 2013</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:lync_server:2013"/>
        <description>Microsoft Lync Server 2013 is installed</description>
        <oval_repository>
          <dates>
            <submitted date="2013-05-17T15:07:42">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-05-21T11:55:37.927-04:00">DRAFT</status_change>
            <status_change date="2013-06-10T04:01:08.247-04:00">INTERIM</status_change>
            <status_change date="2013-07-01T04:00:49.126-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="Check if Microsoft Lync Server 2013 is installed" test_ref="oval:org.mitre.oval:tst:81027"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26515" version="3" class="vulnerability">
      <metadata>
        <title>Allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-2782" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2782"/>
        <description>Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-1773, CVE-2014-1783, CVE-2014-1784, CVE-2014-1786, CVE-2014-1795, CVE-2014-1805, CVE-2014-2758, CVE-2014-2759, CVE-2014-2765, CVE-2014-2766, and CVE-2014-2775.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-08-11T08:31:03">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </submitted>
            <status_change date="2014-09-11T08:03:44.556-04:00">DRAFT</status_change>
            <status_change date="2014-09-29T04:00:24.512-04:00">INTERIM</status_change>
            <status_change date="2014-10-20T04:00:35.742-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16555" test_ref="oval:org.mitre.oval:tst:114960"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20666" test_ref="oval:org.mitre.oval:tst:114734"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16921" test_ref="oval:org.mitre.oval:tst:114739"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21044" test_ref="oval:org.mitre.oval:tst:114922"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16668" test_ref="oval:org.mitre.oval:tst:114145"/>
                <criteria operator="AND" comment="kb2957689 and kb2929437">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 11.0.9600.17041" test_ref="oval:org.mitre.oval:tst:113778"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17126" test_ref="oval:org.mitre.oval:tst:113991"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 8.1 / 2k12 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16668" test_ref="oval:org.mitre.oval:tst:114145"/>
                <criteria operator="AND" comment="kb2957689 and kb2919355">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 11.0.9600.17037" test_ref="oval:org.mitre.oval:tst:114108"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17126" test_ref="oval:org.mitre.oval:tst:113991"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26479" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability - CVE-2014-4056 (MS14-051)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-4056" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4056"/>
        <description>Microsoft Internet Explorer 7 through 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-08-19T08:33:30">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-08-26T16:07:29.754-04:00">DRAFT</status_change>
            <status_change date="2014-09-15T04:00:59.449-04:00">INTERIM</status_change>
            <status_change date="2014-10-06T04:03:41.335-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21397" test_ref="oval:org.mitre.oval:tst:121743"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista/2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19143" test_ref="oval:org.mitre.oval:tst:122338"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23446" test_ref="oval:org.mitre.oval:tst:122105"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23611" test_ref="oval:org.mitre.oval:tst:122198"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19553" test_ref="oval:org.mitre.oval:tst:122307"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23611" test_ref="oval:org.mitre.oval:tst:122198"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18534" test_ref="oval:org.mitre.oval:tst:122429"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22745" test_ref="oval:org.mitre.oval:tst:122320"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16563" test_ref="oval:org.mitre.oval:tst:122010"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20674" test_ref="oval:org.mitre.oval:tst:121838"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17054" test_ref="oval:org.mitre.oval:tst:121473"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21173" test_ref="oval:org.mitre.oval:tst:122251"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26467" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability - CVE-2014-2774 (MS14-051)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-2774" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2774"/>
        <description>Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-2820, CVE-2014-2826, CVE-2014-2827, and CVE-2014-4063.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-08-19T08:33:30">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-08-26T16:08:10.821-04:00">DRAFT</status_change>
            <status_change date="2014-09-15T04:00:59.174-04:00">INTERIM</status_change>
            <status_change date="2014-10-06T04:03:40.631-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5392" test_ref="oval:org.mitre.oval:tst:121772"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21397" test_ref="oval:org.mitre.oval:tst:121743"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista/2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19143" test_ref="oval:org.mitre.oval:tst:122338"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23446" test_ref="oval:org.mitre.oval:tst:122105"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23611" test_ref="oval:org.mitre.oval:tst:122198"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19553" test_ref="oval:org.mitre.oval:tst:122307"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23611" test_ref="oval:org.mitre.oval:tst:122198"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18534" test_ref="oval:org.mitre.oval:tst:122429"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22745" test_ref="oval:org.mitre.oval:tst:122320"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16563" test_ref="oval:org.mitre.oval:tst:122010"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20674" test_ref="oval:org.mitre.oval:tst:121838"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17054" test_ref="oval:org.mitre.oval:tst:121473"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21173" test_ref="oval:org.mitre.oval:tst:122251"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7 / 2k8 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17239" test_ref="oval:org.mitre.oval:tst:122281"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26452" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability - CVE-2014-2818 (MS14-051)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <product>Microsoft Internet Explorer 10</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-2818" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2818"/>
        <description>Microsoft Internet Explorer 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-08-19T08:33:30">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-08-26T16:08:04.469-04:00">DRAFT</status_change>
            <status_change date="2014-09-15T04:00:58.745-04:00">INTERIM</status_change>
            <status_change date="2014-10-06T04:03:39.365-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
        <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
          <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
          <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
          <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
          <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
          <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
        </criteria>
        <criteria operator="OR" comment="Check for vulnerable versions">
          <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17054" test_ref="oval:org.mitre.oval:tst:121473"/>
          <criteria operator="AND" comment="Check for LDR">
            <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21173" test_ref="oval:org.mitre.oval:tst:122251"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26442" version="3" class="vulnerability">
      <metadata>
        <title>Win32k Elevation of Privilege vulnerability - CVE-2014-0318 (MS14-045)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-0318" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0318"/>
        <description>win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 does not properly control access to thread-owned objects, which allows local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-08-19T14:34:18">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-08-26T15:55:08.124-04:00">DRAFT</status_change>
            <status_change date="2014-09-15T04:00:58.530-04:00">INTERIM</status_change>
            <status_change date="2014-10-06T04:03:38.308-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="2K3(all) and vulnerable file version">
          <criteria operator="OR" comment="Either OS">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of win32k.sys is less than 5.2.3790.5398" test_ref="oval:org.mitre.oval:tst:122069"/>
        </criteria>
        <criteria operator="AND" comment="Vista / 2k8 + vulnerable file version">
          <criteria operator="OR" comment="Vista / 2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of win32k.sys is less than 6.0.6002.19150" test_ref="oval:org.mitre.oval:tst:121902"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:81723"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.0.6002.23454" test_ref="oval:org.mitre.oval:tst:122185"/>
            </criteria>
            <criterion comment="Check if the version of Dxgkrnl.sys is less than 7.0.6002.19126" test_ref="oval:org.mitre.oval:tst:122360"/>
            <criteria operator="AND" comment="dxgkrnl.sys LDR">
              <criterion comment="Check if the version of dxgkrnl.sys is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:81004"/>
              <criterion comment="Check if the version of dxgkrnl.sys is less than 7.0.6002.23427" test_ref="oval:org.mitre.oval:tst:122064"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / R2 + vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.18539" test_ref="oval:org.mitre.oval:tst:121806"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:81763"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.22750" test_ref="oval:org.mitre.oval:tst:122188"/>
            </criteria>
            <criterion comment="Check if the version of dxgkrnl.sys is less than 6.1.7601.18510" test_ref="oval:org.mitre.oval:tst:122038"/>
            <criteria operator="AND" comment="dxgkrnl.sys LDR">
              <criterion comment="Check if the version dxgkrnl.sys is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:81058"/>
              <criterion comment="Check if the version of dxgkrnl.sys is less than 6.1.7601.22720" test_ref="oval:org.mitre.oval:tst:122391"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8/2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.17059" test_ref="oval:org.mitre.oval:tst:122363"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:115678"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.21178" test_ref="oval:org.mitre.oval:tst:122110"/>
            </criteria>
            <criterion comment="Check if the version of dxgkrnl.sys is less than 6.2.9200.17031" test_ref="oval:org.mitre.oval:tst:122335"/>
            <criteria operator="AND" comment="dxgkrnl.sys LDR">
              <criterion comment="Check if the version of dxgkrnl.sys is less than 6.2.9200.21148" test_ref="oval:org.mitre.oval:tst:122306"/>
              <criterion comment="Check if the version of dxgkrnl.sys is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:122330"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1 / 2K12 R2and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criteria operator="OR" comment="Either vulnerable file">
            <criterion comment="Check if the version of win32k.sys is less than 6.3.9600.17250" test_ref="oval:org.mitre.oval:tst:122384"/>
            <criterion comment="Check if the version of dxgkrnl.sys is less than 6.3.9600.17210" test_ref="oval:org.mitre.oval:tst:122135"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26422" version="3" class="vulnerability">
      <metadata>
        <title>TrueType font parsing remote code execution vulnerability - CVE-2014-4148 (MS14-058)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-4148" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4148"/>
        <description>win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to execute arbitrary code via a crafted TrueType font, as exploited in the wild in October 2014, aka "TrueType Font Parsing Remote Code Execution Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-10-17T08:40:43">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-10-17T17:49:55.492-04:00">DRAFT</status_change>
            <status_change date="2014-11-03T04:00:11.556-05:00">INTERIM</status_change>
            <status_change date="2014-11-24T04:00:21.971-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Windows Server 2k3 and vulnerable file version">
          <criteria operator="OR" comment="Either OS">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of win32k.sys is less than 5.2.3790.5445" test_ref="oval:org.mitre.oval:tst:124336"/>
        </criteria>
        <criteria operator="AND" comment="Vista / 2k8 + vulnerable file version">
          <criteria operator="OR" comment="Vista / 2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of win32k.sys is less than 6.0.6002.19198" test_ref="oval:org.mitre.oval:tst:125108"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:81723"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.0.6002.23504" test_ref="oval:org.mitre.oval:tst:124868"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / R2 + vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.18615" test_ref="oval:org.mitre.oval:tst:124383"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:81763"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.22823" test_ref="oval:org.mitre.oval:tst:125245"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8/2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.17130" test_ref="oval:org.mitre.oval:tst:125211"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:115678"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.21247" test_ref="oval:org.mitre.oval:tst:124497"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1 / 2K12 R2and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of win32k.sys is less than 6.3.9600.17353" test_ref="oval:org.mitre.oval:tst:124547"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26405" version="3" class="vulnerability">
      <metadata>
        <title>Internet explorer memory corruption vulnerability - CVE-2014-4109 (MS14-052)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-4109" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4109"/>
        <description>Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-2799, CVE-2014-4059, CVE-2014-4065, CVE-2014-4079, CVE-2014-4081, CVE-2014-4083, CVE-2014-4085, CVE-2014-4088, CVE-2014-4090, CVE-2014-4094, CVE-2014-4097, CVE-2014-4100, CVE-2014-4103, CVE-2014-4104, CVE-2014-4105, CVE-2014-4106, CVE-2014-4107, CVE-2014-4108, CVE-2014-4110, and CVE-2014-4111.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-09-12T20:45:43">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-09-17T10:54:30.374-04:00">DRAFT</status_change>
            <status_change date="2014-10-06T04:03:37.174-04:00">INTERIM</status_change>
            <status_change date="2014-10-27T04:00:46.564-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5413" test_ref="oval:org.mitre.oval:tst:123102"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21408" test_ref="oval:org.mitre.oval:tst:123204"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista/2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19165" test_ref="oval:org.mitre.oval:tst:123599"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23470" test_ref="oval:org.mitre.oval:tst:123011"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23619" test_ref="oval:org.mitre.oval:tst:123007"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19561" test_ref="oval:org.mitre.oval:tst:123464"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23619" test_ref="oval:org.mitre.oval:tst:123007"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18571" test_ref="oval:org.mitre.oval:tst:123348"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22777" test_ref="oval:org.mitre.oval:tst:123326"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16575" test_ref="oval:org.mitre.oval:tst:122615"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20691" test_ref="oval:org.mitre.oval:tst:123605"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17088" test_ref="oval:org.mitre.oval:tst:123567"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21207" test_ref="oval:org.mitre.oval:tst:123452"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7, 2k8 r2, win 8 or 2k12 r2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vuln file version">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17280" test_ref="oval:org.mitre.oval:tst:123331"/>
            </criteria>
            <criteria operator="AND" comment="Win 8 / 2k12 r2 and vuln file version">
              <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17278" test_ref="oval:org.mitre.oval:tst:123432"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26400" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability - CVE-2014-2784 (MS14-051)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-2784" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2784"/>
        <description>Microsoft Internet Explorer 8 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-4051.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-08-19T08:33:30">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-08-26T16:07:51.966-04:00">DRAFT</status_change>
            <status_change date="2014-09-15T04:00:58.289-04:00">INTERIM</status_change>
            <status_change date="2014-10-06T04:03:36.770-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23611" test_ref="oval:org.mitre.oval:tst:122198"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19553" test_ref="oval:org.mitre.oval:tst:122307"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23611" test_ref="oval:org.mitre.oval:tst:122198"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18534" test_ref="oval:org.mitre.oval:tst:122429"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22745" test_ref="oval:org.mitre.oval:tst:122320"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16563" test_ref="oval:org.mitre.oval:tst:122010"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20674" test_ref="oval:org.mitre.oval:tst:121838"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17054" test_ref="oval:org.mitre.oval:tst:121473"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21173" test_ref="oval:org.mitre.oval:tst:122251"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7 / 2k8 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17239" test_ref="oval:org.mitre.oval:tst:122281"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26394" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability - CVE-2014-4058 (MS14-051)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-4058" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4058"/>
        <description>Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-08-19T08:33:30">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-08-26T16:08:03.556-04:00">DRAFT</status_change>
            <status_change date="2014-09-15T04:00:57.728-04:00">INTERIM</status_change>
            <status_change date="2014-10-06T04:03:36.377-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16563" test_ref="oval:org.mitre.oval:tst:122010"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20674" test_ref="oval:org.mitre.oval:tst:121838"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17054" test_ref="oval:org.mitre.oval:tst:121473"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21173" test_ref="oval:org.mitre.oval:tst:122251"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7 / 2k8 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17239" test_ref="oval:org.mitre.oval:tst:122281"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26378" version="5" class="vulnerability">
      <metadata>
        <title>Unspecified vulnerability allows remote attackers to bypass Protected Mode</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 8</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2011-1347" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1347"/>
        <description>Unspecified vulnerability in Microsoft Internet Explorer 8 on Windows 7 allows remote attackers to bypass Protected Mode and create arbitrary files by leveraging access to a Low integrity process, as demonstrated by Stephen Fewer as the third of three chained vulnerabilities during a Pwn2Own competition at CanSecWest 2011.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-09-03T08:31:03">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </submitted>
            <status_change date="2014-09-11T08:03:40.643-04:00">DRAFT</status_change>
            <status_change date="2014-09-29T04:00:19.262-04:00">INTERIM</status_change>
            <status_change date="2014-10-20T04:00:27.454-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:26378 - Modified vulnerabilities - a lot of fixes" date="2015-07-22T13:39:00.268-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-07-22T13:41:47.467-04:00">INTERIM</status_change>
            <status_change date="2015-08-10T04:00:27.668-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
        <criteria operator="OR" comment="GDR or LDR Service branch">
          <criterion comment="Mshtml.dll version is less than 8.0.7600.16722" test_ref="oval:org.mitre.oval:tst:42403"/>
          <criteria operator="AND" comment="LDR">
            <criterion comment="Mshtml.dll version is greater than or equal 8.0.7600.20000" test_ref="oval:org.mitre.oval:tst:20848"/>
            <criterion comment="Mshtml.dll version is less than 8.0.7600.20861" test_ref="oval:org.mitre.oval:tst:42393"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26376" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability (CVE-2014-2782) - MS14-035</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-2782" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2782"/>
        <description>Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-1773, CVE-2014-1783, CVE-2014-1784, CVE-2014-1786, CVE-2014-1795, CVE-2014-1805, CVE-2014-2758, CVE-2014-2759, CVE-2014-2765, CVE-2014-2766, and CVE-2014-2775.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-08-11T08:31:03">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </submitted>
            <status_change date="2014-08-13T10:47:58.925-04:00">DRAFT</status_change>
            <status_change date="2014-09-01T04:03:13.376-04:00">INTERIM</status_change>
            <status_change date="2014-09-22T04:00:50.487-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16555" test_ref="oval:org.mitre.oval:tst:114960"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20666" test_ref="oval:org.mitre.oval:tst:114734"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16921" test_ref="oval:org.mitre.oval:tst:114739"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21044" test_ref="oval:org.mitre.oval:tst:114922"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16668" test_ref="oval:org.mitre.oval:tst:114145"/>
                <criteria operator="AND" comment="kb2957689 and kb2929437">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 11.0.9600.17041" test_ref="oval:org.mitre.oval:tst:113778"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17126" test_ref="oval:org.mitre.oval:tst:113991"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 8.1 / 2k12 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16668" test_ref="oval:org.mitre.oval:tst:114145"/>
                <criteria operator="AND" comment="kb2957689 and kb2919355">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 11.0.9600.17037" test_ref="oval:org.mitre.oval:tst:114108"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17126" test_ref="oval:org.mitre.oval:tst:113991"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26355" version="3" class="vulnerability">
      <metadata>
        <title>Microsoft Internet Explorer contains a flaw that may allow bypassing the elevation policy checks in the Enhanced Protected Mode and Protected Mode mechanisms - CVE-2013-4015 (MS13-055)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2013-4015" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4015"/>
        <description>Microsoft Internet Explorer 6 through 10 allows local users to bypass the elevation policy check in the (1) Protected Mode or (2) Enhanced Protected Mode protection mechanism, and consequently gain privileges, by leveraging the ability to execute sandboxed code.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-08-12T08:31:03">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </submitted>
            <status_change date="2014-08-15T10:18:02.005-04:00">DRAFT</status_change>
            <status_change date="2014-09-01T04:03:12.477-04:00">INTERIM</status_change>
            <status_change date="2014-09-22T04:00:48.043-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + Win XP/2K3 + vulnerable file versions">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="Check for vulnerable OS and respective file versions">
            <criteria operator="AND" comment="XP X86 and vulnerable file version">
              <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
              <criterion comment="Check if the version of mshtml.dll is less than 6.0.2900.6400" test_ref="oval:org.mitre.oval:tst:81844"/>
            </criteria>
            <criteria operator="AND" comment="XP X64 / 2K3 and vulnerable file version">
              <criteria operator="OR" comment="XP X64 / 2K3">
                <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5170" test_ref="oval:org.mitre.oval:tst:81724"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 7 + Win XP/2K3/Vista/2K8 + vulnerable file versions">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="Check for vulnerable OS and respective file versions">
            <criteria operator="AND" comment="XP/2K3 and vulnerable file versions">
              <criteria operator="OR" comment="XP / 2K3">
                <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
                <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21342" test_ref="oval:org.mitre.oval:tst:81752"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2K8 and vulnerable file versions">
              <criteria operator="OR" comment="Vista / 2K8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.18861" test_ref="oval:org.mitre.oval:tst:81698"/>
                <criteria operator="AND" comment="Check for LDR range">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23133" test_ref="oval:org.mitre.oval:tst:81717"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + Win XP/2K3/Vista/2K8/Win7/R2 + vulnerable file versions">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="Check for vulnerable OS and respective file versions">
            <criteria operator="AND" comment="XP/2K3 and vulnerable file versions">
              <criteria operator="OR" comment="XP / 2K3">
                <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
                <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23507" test_ref="oval:org.mitre.oval:tst:81827"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2K8 and vulnerable file versions">
              <criteria operator="OR" comment="Vista / 2K8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19443" test_ref="oval:org.mitre.oval:tst:81789"/>
                <criteria operator="AND" comment="Check for LDR range">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23507" test_ref="oval:org.mitre.oval:tst:81827"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18170" test_ref="oval:org.mitre.oval:tst:81431"/>
                <criteria operator="AND" comment="Check for LDR range">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22341" test_ref="oval:org.mitre.oval:tst:81329"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + Win 7/R2/Vista/2K8 + vulnerable file versions">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="Vista/2K8/Win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16496" test_ref="oval:org.mitre.oval:tst:81875"/>
            <criteria operator="AND" comment="Check for LDR range">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20606" test_ref="oval:org.mitre.oval:tst:81808"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + Win 7/R2/Win8/2k12 + vulnerable file versions">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16635" test_ref="oval:org.mitre.oval:tst:81840"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.20000" test_ref="oval:org.mitre.oval:tst:80523"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.20742" test_ref="oval:org.mitre.oval:tst:81835"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26341" version="3" class="vulnerability">
      <metadata>
        <title>Windows installer repair vulnerability - CVE-2014-1814 (MS14-049)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Vista</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-1814" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1814"/>
        <description>The Windows Installer in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges via a crafted application that invokes the repair feature for a different application, aka "Windows Installer Repair Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-08-19T08:35:43">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-08-26T16:02:37.371-04:00">DRAFT</status_change>
            <status_change date="2014-09-15T04:00:56.654-04:00">INTERIM</status_change>
            <status_change date="2014-10-06T04:03:33.154-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista SP2 x86/x64, Server 2008 SP2 32bit/x64/ia64">
          <criteria operator="OR" comment="Check for vulnerable Microsoft Windows OS">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="Check if the version of Consent.exe is less than 6.0.6002.19116" test_ref="oval:org.mitre.oval:tst:122005"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="Check if the version of Consent.exe is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:122057"/>
              <criterion comment="Check if the version of Consent.exe is less than 6.0.6002.23415" test_ref="oval:org.mitre.oval:tst:122266"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 7 x86/x64, Server 2008 R2 x64/ia64">
          <criteria operator="OR" comment="Check for vulnerable Microsoft Windows OS">
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="Check if the version of Consent.exe is less than 6.1.7601.18493" test_ref="oval:org.mitre.oval:tst:122413"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="Check if the version of Consent.exe is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:122395"/>
              <criterion comment="Check if the version of Consent.exe is less than 6.1.7601.22708" test_ref="oval:org.mitre.oval:tst:122273"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="8.1/2012 R2 and vulnerable version">
          <criteria operator="OR" comment="8.1/ 2012 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of Consent.exe is less than 6.3.9600.17198" test_ref="oval:org.mitre.oval:tst:122325"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 2K3">
          <criteria operator="OR" comment="Check for vulnerable Microsoft Windows OS">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of crypt32.dll is less than 5.131.3790.5362" test_ref="oval:org.mitre.oval:tst:122416"/>
        </criteria>
        <criteria operator="AND" comment="Win 8 / 2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criteria operator="AND" comment="Check for LDR range">
              <criterion comment="Check if the version of Consent.exe is less than 6.2.9200.21139" test_ref="oval:org.mitre.oval:tst:122019"/>
              <criterion comment="Check if the version of Consent.exe is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:122075"/>
            </criteria>
            <criterion comment="Check if the version of Consent.exe is less than 6.2.9200.17022" test_ref="oval:org.mitre.oval:tst:121864"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26334" version="3" class="vulnerability">
      <metadata>
        <title>Internet explorer memory corruption vulnerability - CVE-2014-4102 (MS14-052)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-4102" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4102"/>
        <description>Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-4080, CVE-2014-4089, and CVE-2014-4091.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-09-12T20:45:43">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-09-17T10:53:57.475-04:00">DRAFT</status_change>
            <status_change date="2014-10-06T04:03:32.770-04:00">INTERIM</status_change>
            <status_change date="2014-10-27T04:00:41.217-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17088" test_ref="oval:org.mitre.oval:tst:123567"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21207" test_ref="oval:org.mitre.oval:tst:123452"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7, 2k8 r2, win 8 or 2k12 r2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vuln file version">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17280" test_ref="oval:org.mitre.oval:tst:123331"/>
            </criteria>
            <criteria operator="AND" comment="Win 8 / 2k12 r2 and vuln file version">
              <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17278" test_ref="oval:org.mitre.oval:tst:123432"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26322" version="3" class="vulnerability">
      <metadata>
        <title>Font Double-Fetch vulnerability - CVE-2014-1819 (MS14-045)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-1819" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1819"/>
        <description>win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 does not properly control access to objects associated with font files, which allows local users to gain privileges via a crafted file, aka "Font Double-Fetch Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-08-19T14:34:18">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-08-26T15:55:13.702-04:00">DRAFT</status_change>
            <status_change date="2014-09-15T04:00:56.163-04:00">INTERIM</status_change>
            <status_change date="2014-10-06T04:03:32.459-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="2K3(all) and vulnerable file version">
          <criteria operator="OR" comment="Either OS">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of win32k.sys is less than 5.2.3790.5398" test_ref="oval:org.mitre.oval:tst:122069"/>
        </criteria>
        <criteria operator="AND" comment="Vista / 2k8 + vulnerable file version">
          <criteria operator="OR" comment="Vista / 2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of win32k.sys is less than 6.0.6002.19150" test_ref="oval:org.mitre.oval:tst:121902"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:81723"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.0.6002.23454" test_ref="oval:org.mitre.oval:tst:122185"/>
            </criteria>
            <criterion comment="Check if the version of Dxgkrnl.sys is less than 7.0.6002.19126" test_ref="oval:org.mitre.oval:tst:122360"/>
            <criteria operator="AND" comment="dxgkrnl.sys LDR">
              <criterion comment="Check if the version of dxgkrnl.sys is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:81004"/>
              <criterion comment="Check if the version of dxgkrnl.sys is less than 7.0.6002.23427" test_ref="oval:org.mitre.oval:tst:122064"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / R2 + vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.18539" test_ref="oval:org.mitre.oval:tst:121806"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:81763"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.22750" test_ref="oval:org.mitre.oval:tst:122188"/>
            </criteria>
            <criterion comment="Check if the version of dxgkrnl.sys is less than 6.1.7601.18510" test_ref="oval:org.mitre.oval:tst:122038"/>
            <criteria operator="AND" comment="dxgkrnl.sys LDR">
              <criterion comment="Check if the version dxgkrnl.sys is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:81058"/>
              <criterion comment="Check if the version of dxgkrnl.sys is less than 6.1.7601.22720" test_ref="oval:org.mitre.oval:tst:122391"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8/2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.17059" test_ref="oval:org.mitre.oval:tst:122363"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:115678"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.21178" test_ref="oval:org.mitre.oval:tst:122110"/>
            </criteria>
            <criterion comment="Check if the version of dxgkrnl.sys is less than 6.2.9200.17031" test_ref="oval:org.mitre.oval:tst:122335"/>
            <criteria operator="AND" comment="dxgkrnl.sys LDR">
              <criterion comment="Check if the version of dxgkrnl.sys is less than 6.2.9200.21148" test_ref="oval:org.mitre.oval:tst:122306"/>
              <criterion comment="Check if the version of dxgkrnl.sys is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:122330"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1 / 2K12 R2and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criteria operator="OR" comment="Either vulnerable file">
            <criterion comment="Check if the version of win32k.sys is less than 6.3.9600.17250" test_ref="oval:org.mitre.oval:tst:122384"/>
            <criterion comment="Check if the version of dxgkrnl.sys is less than 6.3.9600.17210" test_ref="oval:org.mitre.oval:tst:122135"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26321" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability - CVE-2014-4052 (MS14-051)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-4052" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4052"/>
        <description>Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-08-19T08:33:30">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-08-26T16:07:53.407-04:00">DRAFT</status_change>
            <status_change date="2014-09-15T04:00:55.963-04:00">INTERIM</status_change>
            <status_change date="2014-10-06T04:03:32.265-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16563" test_ref="oval:org.mitre.oval:tst:122010"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20674" test_ref="oval:org.mitre.oval:tst:121838"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17054" test_ref="oval:org.mitre.oval:tst:121473"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21173" test_ref="oval:org.mitre.oval:tst:122251"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26313" version="3" class="vulnerability">
      <metadata>
        <title>Internet explorer memory corruption vulnerability - CVE-2014-4110 (MS14-052)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-4110" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4110"/>
        <description>Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-2799, CVE-2014-4059, CVE-2014-4065, CVE-2014-4079, CVE-2014-4081, CVE-2014-4083, CVE-2014-4085, CVE-2014-4088, CVE-2014-4090, CVE-2014-4094, CVE-2014-4097, CVE-2014-4100, CVE-2014-4103, CVE-2014-4104, CVE-2014-4105, CVE-2014-4106, CVE-2014-4107, CVE-2014-4108, CVE-2014-4109, and CVE-2014-4111.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-09-12T20:45:43">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-09-17T10:55:07.786-04:00">DRAFT</status_change>
            <status_change date="2014-10-06T04:03:31.810-04:00">INTERIM</status_change>
            <status_change date="2014-10-27T04:00:39.629-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5413" test_ref="oval:org.mitre.oval:tst:123102"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21408" test_ref="oval:org.mitre.oval:tst:123204"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista/2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19165" test_ref="oval:org.mitre.oval:tst:123599"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23470" test_ref="oval:org.mitre.oval:tst:123011"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23619" test_ref="oval:org.mitre.oval:tst:123007"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19561" test_ref="oval:org.mitre.oval:tst:123464"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23619" test_ref="oval:org.mitre.oval:tst:123007"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18571" test_ref="oval:org.mitre.oval:tst:123348"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22777" test_ref="oval:org.mitre.oval:tst:123326"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16575" test_ref="oval:org.mitre.oval:tst:122615"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20691" test_ref="oval:org.mitre.oval:tst:123605"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17088" test_ref="oval:org.mitre.oval:tst:123567"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21207" test_ref="oval:org.mitre.oval:tst:123452"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7, 2k8 r2, win 8 or 2k12 r2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vuln file version">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17280" test_ref="oval:org.mitre.oval:tst:123331"/>
            </criteria>
            <criteria operator="AND" comment="Win 8 / 2k12 r2 and vuln file version">
              <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17278" test_ref="oval:org.mitre.oval:tst:123432"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26306" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability - CVE-2014-2817 (MS14-051)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-2817" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2817"/>
        <description>Microsoft Internet Explorer 6 through 11 allows remote attackers to gain privileges via a crafted web site, aka "Internet Explorer Elevation of Privilege Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-08-19T08:33:30">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-08-26T16:07:49.553-04:00">DRAFT</status_change>
            <status_change date="2014-09-15T04:00:55.312-04:00">INTERIM</status_change>
            <status_change date="2014-10-06T04:03:31.490-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5392" test_ref="oval:org.mitre.oval:tst:121772"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21397" test_ref="oval:org.mitre.oval:tst:121743"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista/2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19143" test_ref="oval:org.mitre.oval:tst:122338"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23446" test_ref="oval:org.mitre.oval:tst:122105"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23611" test_ref="oval:org.mitre.oval:tst:122198"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19553" test_ref="oval:org.mitre.oval:tst:122307"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23611" test_ref="oval:org.mitre.oval:tst:122198"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18534" test_ref="oval:org.mitre.oval:tst:122429"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22745" test_ref="oval:org.mitre.oval:tst:122320"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16563" test_ref="oval:org.mitre.oval:tst:122010"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20674" test_ref="oval:org.mitre.oval:tst:121838"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17054" test_ref="oval:org.mitre.oval:tst:121473"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21173" test_ref="oval:org.mitre.oval:tst:122251"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7 / 2k8 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17239" test_ref="oval:org.mitre.oval:tst:122281"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26305" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability - CVE-2014-2819 (MS14-051)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-2819" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2819"/>
        <description>Microsoft Internet Explorer 7 through 11 allows remote attackers to gain privileges via a crafted web site, aka "Internet Explorer Elevation of Privilege Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-08-19T08:33:30">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-08-26T16:08:13.211-04:00">DRAFT</status_change>
            <status_change date="2014-09-15T04:00:55.009-04:00">INTERIM</status_change>
            <status_change date="2014-10-06T04:03:31.269-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21397" test_ref="oval:org.mitre.oval:tst:121743"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista/2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19143" test_ref="oval:org.mitre.oval:tst:122338"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23446" test_ref="oval:org.mitre.oval:tst:122105"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23611" test_ref="oval:org.mitre.oval:tst:122198"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19553" test_ref="oval:org.mitre.oval:tst:122307"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23611" test_ref="oval:org.mitre.oval:tst:122198"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18534" test_ref="oval:org.mitre.oval:tst:122429"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22745" test_ref="oval:org.mitre.oval:tst:122320"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16563" test_ref="oval:org.mitre.oval:tst:122010"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20674" test_ref="oval:org.mitre.oval:tst:121838"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17054" test_ref="oval:org.mitre.oval:tst:121473"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21173" test_ref="oval:org.mitre.oval:tst:122251"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7 / 2k8 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17239" test_ref="oval:org.mitre.oval:tst:122281"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26300" version="3" class="vulnerability">
      <metadata>
        <title>SharePoint Page Content Vulnerability (CVE-2014-2816) - MS14-050</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft SharePoint Foundation 2013</product>
          <product>Microsoft SharePoint Server 2013</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-2816" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2816"/>
        <description>Microsoft SharePoint Server 2013 Gold and SP1 and SharePoint Foundation 2013 Gold and SP1 allow remote authenticated users to gain privileges via a Trojan horse app that executes a custom action in the context of the SharePoint extensibility model, aka "SharePoint Page Content Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-08-19T14:12:20">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-08-26T16:05:02.551-04:00">DRAFT</status_change>
            <status_change date="2014-09-15T04:00:54.428-04:00">INTERIM</status_change>
            <status_change date="2014-10-06T04:03:31.051-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="Sharepoint Server or Foundation 2013">
          <extend_definition comment="Microsoft SharePoint Server 2013 is installed" definition_ref="oval:org.mitre.oval:def:16325"/>
          <extend_definition comment="Microsoft SharePoint Foundation 2013 is installed" definition_ref="oval:org.mitre.oval:def:19090"/>
        </criteria>
        <criterion comment="Check if the version of wsssetup.dll is less than 15.0.4641.1000" test_ref="oval:org.mitre.oval:tst:121842"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26288" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability - CVE-2014-4050 (MS14-051)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-4050" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4050"/>
        <description>Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-2796, CVE-2014-2808, CVE-2014-2825, CVE-2014-4055, and CVE-2014-4067.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-08-19T08:33:30">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-08-26T16:07:34.431-04:00">DRAFT</status_change>
            <status_change date="2014-09-15T04:00:53.911-04:00">INTERIM</status_change>
            <status_change date="2014-10-06T04:03:30.759-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17054" test_ref="oval:org.mitre.oval:tst:121473"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21173" test_ref="oval:org.mitre.oval:tst:122251"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7 / 2k8 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17239" test_ref="oval:org.mitre.oval:tst:122281"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26275" version="6" class="vulnerability">
      <metadata>
        <title>CSyncBasePlayer use after free vulnerability - CVE-2014-4060 (MS14-043)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Vista</platform>
          <product>Microsoft Windows Media Center</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-4060" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4060"/>
        <description>Use-after-free vulnerability in MCPlayer.dll in Microsoft Windows Media Center TV Pack for Windows Vista, Windows 7 SP1, and Windows Media Center for Windows 8 and 8.1 allows remote attackers to execute arbitrary code via a crafted Office document that triggers deletion of a CSyncBasePlayer object, aka "CSyncBasePlayer Use After Free Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-08-19T09:06:03">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-08-26T15:52:19.080-04:00">DRAFT</status_change>
            <status_change date="2014-09-15T04:00:52.703-04:00">INTERIM</status_change>
            <status_change date="2014-10-06T04:03:30.493-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:26275 - Modified vulnerabilities - a lot of fixes" date="2015-07-22T13:39:00.268-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-07-22T13:41:47.343-04:00">INTERIM</status_change>
            <status_change date="2015-08-10T04:00:27.326-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Microsoft Windows Media Center is installed" definition_ref="oval:org.mitre.oval:def:29080"/>
        <criteria operator="OR" comment="VULNERABLE versions">
          <criteria operator="AND" comment="Vista vulnerable file version">
            <criteria operator="OR" comment="Vista base">
              <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
              <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            </criteria>
            <criterion comment="Check if the version of Mcplayer.dll is less than 6.1.1000.18324" test_ref="oval:org.mitre.oval:tst:122308"/>
          </criteria>
          <criteria operator="AND" comment="Win 7 base and vulnerable file version">
            <criteria operator="OR" comment="Win 7">
              <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
              <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            </criteria>
            <criteria operator="OR" comment="Check for vulnerable version">
              <criterion comment="Check if the version of Mcplayer.dll is less than 6.1.7601.18523" test_ref="oval:org.mitre.oval:tst:122337"/>
              <criteria operator="AND" comment="LDR range">
                <criterion comment="Check if the version of Mcplayer.dll is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:122224"/>
                <criterion comment="Check if the version of Mcplayer.dll is less than 6.1.7601.22733" test_ref="oval:org.mitre.oval:tst:121807"/>
              </criteria>
            </criteria>
          </criteria>
          <criteria operator="AND" comment="Windows 8 and vulnerable file version">
            <criteria operator="OR" comment="Windows 8 32/64 bit">
              <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
              <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            </criteria>
            <criteria operator="OR" comment="Check for vulnerable version">
              <criterion comment="Check if the version of Mcplayer.dll is less than 6.2.9200.17045" test_ref="oval:org.mitre.oval:tst:122332"/>
              <criteria operator="AND" comment="Check for LDR">
                <criterion comment="Check if the version of Mcplayer.dll is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:121544"/>
                <criterion comment="Check if the version of Mcplayer.dll is less than 6.2.9200.21162" test_ref="oval:org.mitre.oval:tst:121999"/>
              </criteria>
            </criteria>
          </criteria>
          <criteria operator="AND" comment="Win 8.1 and vulnerable file version">
            <criteria operator="OR" comment="Win 8.1 32 / 64 bit">
              <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
              <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            </criteria>
            <criterion comment="Check if the version of Mcplayer.dll is less than 6.3.9600.17224" test_ref="oval:org.mitre.oval:tst:121753"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29080" version="3" class="inventory">
      <metadata>
        <title>Microsoft Windows Media Center is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Vista</platform>
          <product>Microsoft Windows Media Center</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:windows_media_center"/>
        <description>Microsoft Windows Media Center is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-05T08:31:03">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </submitted>
            <status_change date="2015-06-10T14:07:25.765-04:00">DRAFT</status_change>
            <status_change date="2015-06-29T04:00:09.396-04:00">INTERIM</status_change>
            <status_change date="2015-07-20T04:00:13.458-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="Media Center is installed" test_ref="oval:org.mitre.oval:tst:42482"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26242" version="3" class="vulnerability">
      <metadata>
        <title>LRPC ASLR Bypass Vulnerability - CVE-2014-0316 (MS14-047)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-0316" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0316"/>
        <description>Memory leak in the Local RPC (LRPC) server implementation in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to cause a denial of service (memory consumption) and bypass the ASLR protection mechanism via a crafted client that sends messages with an invalid data view, aka "LRPC ASLR Bypass Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-08-19T09:59:11">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-08-26T15:58:49.332-04:00">DRAFT</status_change>
            <status_change date="2014-09-15T04:00:49.498-04:00">INTERIM</status_change>
            <status_change date="2014-10-06T04:03:29.671-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Win 7 / R2 and vulnerable file version">
          <criteria operator="OR" comment="Win 7/ R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of Rpcrt4.dll is less than 6.1.7601.18532" test_ref="oval:org.mitre.oval:tst:122167"/>
            <criteria operator="AND" comment="LDR range">
              <criterion comment="Check if the version of rpcrt4.dll is greater than or equal 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:85227"/>
              <criterion comment="Check if the version of rpcrt4.dll is less than 6.1.7601.22743" test_ref="oval:org.mitre.oval:tst:122210"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Windows 8 / 2012 and vulnerable file version">
          <criteria operator="OR" comment="Win8/2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of Rpcrt4.dll is less than 6.2.9200.17037" test_ref="oval:org.mitre.oval:tst:121646"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of rpcrt4.dll is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:122334"/>
              <criterion comment="Check if the version of rpcrt4.dll is less than 6.2.9200.21154" test_ref="oval:org.mitre.oval:tst:122324"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1/2k12 R2 and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of Rpcrt4.dll is less than 6.3.9600.17216" test_ref="oval:org.mitre.oval:tst:122059"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26227" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability - CVE-2014-2796 (MS14-051)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-2796" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2796"/>
        <description>Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-2808, CVE-2014-2825, CVE-2014-4050, CVE-2014-4055, and CVE-2014-4067.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-08-19T08:33:30">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-08-26T16:07:58.583-04:00">DRAFT</status_change>
            <status_change date="2014-09-15T04:00:47.897-04:00">INTERIM</status_change>
            <status_change date="2014-10-06T04:03:29.526-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17054" test_ref="oval:org.mitre.oval:tst:121473"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21173" test_ref="oval:org.mitre.oval:tst:122251"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7 / 2k8 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17239" test_ref="oval:org.mitre.oval:tst:122281"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26164" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability - CVE-2014-4055 (MS14-051)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-4055" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4055"/>
        <description>Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-2796, CVE-2014-2808, CVE-2014-2825, CVE-2014-4050, and CVE-2014-4067.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-08-19T08:33:30">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-08-26T16:07:57.441-04:00">DRAFT</status_change>
            <status_change date="2014-09-15T04:00:42.863-04:00">INTERIM</status_change>
            <status_change date="2014-10-06T04:03:26.660-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17054" test_ref="oval:org.mitre.oval:tst:121473"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21173" test_ref="oval:org.mitre.oval:tst:122251"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7 / 2k8 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17239" test_ref="oval:org.mitre.oval:tst:122281"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26160" version="3" class="vulnerability">
      <metadata>
        <title>Windows OLE remote code execution vulnerability - CVE-2014-4114 (MS14-060)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-4114" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4114"/>
        <description>Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allow remote attackers to execute arbitrary code via a crafted OLE object in an Office document, as exploited in the wild with a "Sandworm" attack in June through October 2014, aka "Windows OLE Remote Code Execution Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-10-17T08:40:43">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-10-17T18:05:09.984-04:00">DRAFT</status_change>
            <status_change date="2014-11-03T04:00:06.437-05:00">INTERIM</status_change>
            <status_change date="2014-11-24T04:00:09.529-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vista / 2k8 + vulnerable file version">
          <criteria operator="OR" comment="Vista / 2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="Check for LDR/GDR">
            <criterion comment="Check if version of Packager.dll is less than 6.0.6002.19192" test_ref="oval:org.mitre.oval:tst:124892"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if version of Packager.dll is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:125246"/>
              <criterion comment="Check if version of Packager.dll is less than 6.0.6002.23496" test_ref="oval:org.mitre.oval:tst:125013"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / R2 + vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="Check for LDR/GDR">
            <criterion comment="Check if version of Packager.dll is less than 6.1.7601.18601" test_ref="oval:org.mitre.oval:tst:125012"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if version of Packager.dll is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:125217"/>
              <criterion comment="Check if version of Packager.dll is less than 6.1.7601.22809" test_ref="oval:org.mitre.oval:tst:125084"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8/2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Packager.dll is less than 6.2.9200.21237" test_ref="oval:org.mitre.oval:tst:125102"/>
              <criterion comment="Check if the version of Packager.dll is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:124862"/>
            </criteria>
            <criterion comment="Check if the version of Packager.dll is less than 6.2.9200.17121" test_ref="oval:org.mitre.oval:tst:125199"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1 / 2K12 R2and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of packager.dll is less than 6.3.9600.17341" test_ref="oval:org.mitre.oval:tst:124841"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26158" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability - CVE-2014-2825 (MS14-051)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-2825" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2825"/>
        <description>Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-2796, CVE-2014-2808, CVE-2014-4050, CVE-2014-4055, and CVE-2014-4067.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-08-19T08:33:30">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-08-26T16:08:05.620-04:00">DRAFT</status_change>
            <status_change date="2014-09-15T04:00:42.656-04:00">INTERIM</status_change>
            <status_change date="2014-10-06T04:03:26.535-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17054" test_ref="oval:org.mitre.oval:tst:121473"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21173" test_ref="oval:org.mitre.oval:tst:122251"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7 / 2k8 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17239" test_ref="oval:org.mitre.oval:tst:122281"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26136" version="3" class="vulnerability">
      <metadata>
        <title>Windows kernel pool allocation vulnerability - CVE-2014-4064 (MS14-045)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-4064" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4064"/>
        <description>The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 do not properly handle use of the paged kernel pool for allocation of uninitialized memory, which allows local users to obtain sensitive information about kernel addresses via a crafted application, aka "Windows Kernel Pool Allocation Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-08-19T14:34:18">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-08-26T15:55:10.799-04:00">DRAFT</status_change>
            <status_change date="2014-09-15T04:00:38.941-04:00">INTERIM</status_change>
            <status_change date="2014-10-06T04:03:25.606-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vista / 2k8 + vulnerable file version">
          <criteria operator="OR" comment="Vista / 2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of win32k.sys is less than 6.0.6002.19150" test_ref="oval:org.mitre.oval:tst:121902"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:81723"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.0.6002.23454" test_ref="oval:org.mitre.oval:tst:122185"/>
            </criteria>
            <criterion comment="Check if the version of Dxgkrnl.sys is less than 7.0.6002.19126" test_ref="oval:org.mitre.oval:tst:122360"/>
            <criteria operator="AND" comment="dxgkrnl.sys LDR">
              <criterion comment="Check if the version of dxgkrnl.sys is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:81004"/>
              <criterion comment="Check if the version of dxgkrnl.sys is less than 7.0.6002.23427" test_ref="oval:org.mitre.oval:tst:122064"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / R2 + vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.18539" test_ref="oval:org.mitre.oval:tst:121806"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:81763"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.22750" test_ref="oval:org.mitre.oval:tst:122188"/>
            </criteria>
            <criterion comment="Check if the version of dxgkrnl.sys is less than 6.1.7601.18510" test_ref="oval:org.mitre.oval:tst:122038"/>
            <criteria operator="AND" comment="dxgkrnl.sys LDR">
              <criterion comment="Check if the version dxgkrnl.sys is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:81058"/>
              <criterion comment="Check if the version of dxgkrnl.sys is less than 6.1.7601.22720" test_ref="oval:org.mitre.oval:tst:122391"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8/2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.17059" test_ref="oval:org.mitre.oval:tst:122363"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:115678"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.21178" test_ref="oval:org.mitre.oval:tst:122110"/>
            </criteria>
            <criterion comment="Check if the version of dxgkrnl.sys is less than 6.2.9200.17031" test_ref="oval:org.mitre.oval:tst:122335"/>
            <criteria operator="AND" comment="dxgkrnl.sys LDR">
              <criterion comment="Check if the version of dxgkrnl.sys is less than 6.2.9200.21148" test_ref="oval:org.mitre.oval:tst:122306"/>
              <criterion comment="Check if the version of dxgkrnl.sys is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:122330"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1 / 2K12 R2and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criteria operator="OR" comment="Either vulnerable file">
            <criterion comment="Check if the version of win32k.sys is less than 6.3.9600.17250" test_ref="oval:org.mitre.oval:tst:122384"/>
            <criterion comment="Check if the version of dxgkrnl.sys is less than 6.3.9600.17210" test_ref="oval:org.mitre.oval:tst:122135"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26130" version="3" class="vulnerability">
      <metadata>
        <title>Internet explorer memory corruption vulnerability - CVE-2014-4091 (MS14-052)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-4091" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4091"/>
        <description>Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-4080, CVE-2014-4089, and CVE-2014-4102.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-09-12T20:45:43">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-09-17T10:54:24.370-04:00">DRAFT</status_change>
            <status_change date="2014-10-06T04:03:25.269-04:00">INTERIM</status_change>
            <status_change date="2014-10-27T04:00:31.391-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17088" test_ref="oval:org.mitre.oval:tst:123567"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21207" test_ref="oval:org.mitre.oval:tst:123452"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7, 2k8 r2, win 8 or 2k12 r2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vuln file version">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17280" test_ref="oval:org.mitre.oval:tst:123331"/>
            </criteria>
            <criteria operator="AND" comment="Win 8 / 2k12 r2 and vuln file version">
              <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17278" test_ref="oval:org.mitre.oval:tst:123432"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26127" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability - CVE-2014-4067 (MS14-051)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-4067" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4067"/>
        <description>Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-2796, CVE-2014-2808, CVE-2014-2825, CVE-2014-4050, and CVE-2014-4055.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-08-19T08:33:30">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-08-26T16:07:35.636-04:00">DRAFT</status_change>
            <status_change date="2014-09-15T04:00:38.728-04:00">INTERIM</status_change>
            <status_change date="2014-10-06T04:03:24.957-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17054" test_ref="oval:org.mitre.oval:tst:121473"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21173" test_ref="oval:org.mitre.oval:tst:122251"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7 / 2k8 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17239" test_ref="oval:org.mitre.oval:tst:122281"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26121" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability - CVE-2014-2826 (MS14-051)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-2826" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2826"/>
        <description>Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-2774, CVE-2014-2820, CVE-2014-2827, and CVE-2014-4063.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-08-19T08:33:30">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-08-26T16:07:45.677-04:00">DRAFT</status_change>
            <status_change date="2014-09-15T04:00:38.151-04:00">INTERIM</status_change>
            <status_change date="2014-10-06T04:03:24.508-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5392" test_ref="oval:org.mitre.oval:tst:121772"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21397" test_ref="oval:org.mitre.oval:tst:121743"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista/2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19143" test_ref="oval:org.mitre.oval:tst:122338"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23446" test_ref="oval:org.mitre.oval:tst:122105"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23611" test_ref="oval:org.mitre.oval:tst:122198"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19553" test_ref="oval:org.mitre.oval:tst:122307"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23611" test_ref="oval:org.mitre.oval:tst:122198"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18534" test_ref="oval:org.mitre.oval:tst:122429"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22745" test_ref="oval:org.mitre.oval:tst:122320"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16563" test_ref="oval:org.mitre.oval:tst:122010"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20674" test_ref="oval:org.mitre.oval:tst:121838"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17054" test_ref="oval:org.mitre.oval:tst:121473"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21173" test_ref="oval:org.mitre.oval:tst:122251"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7 / 2k8 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17239" test_ref="oval:org.mitre.oval:tst:122281"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26120" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability - CVE-2014-4063 (MS14-051)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-4063" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4063"/>
        <description>Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-2774, CVE-2014-2820, CVE-2014-2826, and CVE-2014-2827.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-08-19T08:33:30">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-08-26T16:07:42.605-04:00">DRAFT</status_change>
            <status_change date="2014-09-15T04:00:37.885-04:00">INTERIM</status_change>
            <status_change date="2014-10-06T04:03:24.251-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5392" test_ref="oval:org.mitre.oval:tst:121772"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21397" test_ref="oval:org.mitre.oval:tst:121743"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista/2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19143" test_ref="oval:org.mitre.oval:tst:122338"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23446" test_ref="oval:org.mitre.oval:tst:122105"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23611" test_ref="oval:org.mitre.oval:tst:122198"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19553" test_ref="oval:org.mitre.oval:tst:122307"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23611" test_ref="oval:org.mitre.oval:tst:122198"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18534" test_ref="oval:org.mitre.oval:tst:122429"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22745" test_ref="oval:org.mitre.oval:tst:122320"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16563" test_ref="oval:org.mitre.oval:tst:122010"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20674" test_ref="oval:org.mitre.oval:tst:121838"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17054" test_ref="oval:org.mitre.oval:tst:121473"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21173" test_ref="oval:org.mitre.oval:tst:122251"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7 / 2k8 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17239" test_ref="oval:org.mitre.oval:tst:122281"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26109" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability - CVE-2014-2827 (MS14-051)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-2827" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2827"/>
        <description>Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-2774, CVE-2014-2820, CVE-2014-2826, and CVE-2014-4063.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-08-19T08:33:30">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-08-26T16:07:56.365-04:00">DRAFT</status_change>
            <status_change date="2014-09-15T04:00:37.195-04:00">INTERIM</status_change>
            <status_change date="2014-10-06T04:03:23.893-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5392" test_ref="oval:org.mitre.oval:tst:121772"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21397" test_ref="oval:org.mitre.oval:tst:121743"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista/2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19143" test_ref="oval:org.mitre.oval:tst:122338"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23446" test_ref="oval:org.mitre.oval:tst:122105"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23611" test_ref="oval:org.mitre.oval:tst:122198"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19553" test_ref="oval:org.mitre.oval:tst:122307"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23611" test_ref="oval:org.mitre.oval:tst:122198"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18534" test_ref="oval:org.mitre.oval:tst:122429"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22745" test_ref="oval:org.mitre.oval:tst:122320"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16563" test_ref="oval:org.mitre.oval:tst:122010"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20674" test_ref="oval:org.mitre.oval:tst:121838"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17054" test_ref="oval:org.mitre.oval:tst:121473"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21173" test_ref="oval:org.mitre.oval:tst:122251"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7 / 2k8 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17239" test_ref="oval:org.mitre.oval:tst:122281"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26092" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability - CVE-2014-4051 (MS14-051)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-4051" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4051"/>
        <description>Microsoft Internet Explorer 8 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-2784.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-08-19T08:33:30">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-08-26T16:08:01.531-04:00">DRAFT</status_change>
            <status_change date="2014-09-15T04:00:35.861-04:00">INTERIM</status_change>
            <status_change date="2014-10-06T04:03:23.049-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23611" test_ref="oval:org.mitre.oval:tst:122198"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19553" test_ref="oval:org.mitre.oval:tst:122307"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23611" test_ref="oval:org.mitre.oval:tst:122198"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18534" test_ref="oval:org.mitre.oval:tst:122429"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22745" test_ref="oval:org.mitre.oval:tst:122320"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16563" test_ref="oval:org.mitre.oval:tst:122010"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20674" test_ref="oval:org.mitre.oval:tst:121838"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17054" test_ref="oval:org.mitre.oval:tst:121473"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21173" test_ref="oval:org.mitre.oval:tst:122251"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7 / 2k8 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17239" test_ref="oval:org.mitre.oval:tst:122281"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26084" version="3" class="vulnerability">
      <metadata>
        <title>Internet explorer memory corruption vulnerability - CVE-2014-4094 (MS14-052)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-4094" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4094"/>
        <description>Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-2799, CVE-2014-4059, CVE-2014-4065, CVE-2014-4079, CVE-2014-4081, CVE-2014-4083, CVE-2014-4085, CVE-2014-4088, CVE-2014-4090, CVE-2014-4097, CVE-2014-4100, CVE-2014-4103, CVE-2014-4104, CVE-2014-4105, CVE-2014-4106, CVE-2014-4107, CVE-2014-4108, CVE-2014-4109, CVE-2014-4110, and CVE-2014-4111.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-09-12T20:45:43">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-09-17T10:54:47.296-04:00">DRAFT</status_change>
            <status_change date="2014-10-06T04:03:22.648-04:00">INTERIM</status_change>
            <status_change date="2014-10-27T04:00:28.012-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5413" test_ref="oval:org.mitre.oval:tst:123102"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21408" test_ref="oval:org.mitre.oval:tst:123204"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista/2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19165" test_ref="oval:org.mitre.oval:tst:123599"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23470" test_ref="oval:org.mitre.oval:tst:123011"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23619" test_ref="oval:org.mitre.oval:tst:123007"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19561" test_ref="oval:org.mitre.oval:tst:123464"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23619" test_ref="oval:org.mitre.oval:tst:123007"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18571" test_ref="oval:org.mitre.oval:tst:123348"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22777" test_ref="oval:org.mitre.oval:tst:123326"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16575" test_ref="oval:org.mitre.oval:tst:122615"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20691" test_ref="oval:org.mitre.oval:tst:123605"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17088" test_ref="oval:org.mitre.oval:tst:123567"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21207" test_ref="oval:org.mitre.oval:tst:123452"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7, 2k8 r2, win 8 or 2k12 r2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vuln file version">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17280" test_ref="oval:org.mitre.oval:tst:123331"/>
            </criteria>
            <criteria operator="AND" comment="Win 8 / 2k12 r2 and vuln file version">
              <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17278" test_ref="oval:org.mitre.oval:tst:123432"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26040" version="3" class="vulnerability">
      <metadata>
        <title>Internet explorer memory corruption vulnerability - CVE-2014-4085 (MS14-052)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-4085" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4085"/>
        <description>Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-2799, CVE-2014-4059, CVE-2014-4065, CVE-2014-4079, CVE-2014-4081, CVE-2014-4083, CVE-2014-4088, CVE-2014-4090, CVE-2014-4094, CVE-2014-4097, CVE-2014-4100, CVE-2014-4103, CVE-2014-4104, CVE-2014-4105, CVE-2014-4106, CVE-2014-4107, CVE-2014-4108, CVE-2014-4109, CVE-2014-4110, and CVE-2014-4111.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-09-12T20:45:43">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-09-17T10:54:49.873-04:00">DRAFT</status_change>
            <status_change date="2014-10-06T04:03:21.321-04:00">INTERIM</status_change>
            <status_change date="2014-10-27T04:00:24.631-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5413" test_ref="oval:org.mitre.oval:tst:123102"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21408" test_ref="oval:org.mitre.oval:tst:123204"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista/2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19165" test_ref="oval:org.mitre.oval:tst:123599"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23470" test_ref="oval:org.mitre.oval:tst:123011"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23619" test_ref="oval:org.mitre.oval:tst:123007"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19561" test_ref="oval:org.mitre.oval:tst:123464"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23619" test_ref="oval:org.mitre.oval:tst:123007"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18571" test_ref="oval:org.mitre.oval:tst:123348"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22777" test_ref="oval:org.mitre.oval:tst:123326"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16575" test_ref="oval:org.mitre.oval:tst:122615"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20691" test_ref="oval:org.mitre.oval:tst:123605"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17088" test_ref="oval:org.mitre.oval:tst:123567"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21207" test_ref="oval:org.mitre.oval:tst:123452"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7, 2k8 r2, win 8 or 2k12 r2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vuln file version">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17280" test_ref="oval:org.mitre.oval:tst:123331"/>
            </criteria>
            <criteria operator="AND" comment="Win 8 / 2k12 r2 and vuln file version">
              <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17278" test_ref="oval:org.mitre.oval:tst:123432"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26009" version="3" class="vulnerability">
      <metadata>
        <title>Internet explorer memory corruption vulnerability - CVE-2014-4084 (MS14-052)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <product>Microsoft Internet Explorer 10</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-4084" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4084"/>
        <description>Microsoft Internet Explorer 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-4093.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-09-12T20:45:43">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-09-17T10:54:44.596-04:00">DRAFT</status_change>
            <status_change date="2014-10-06T04:03:21.113-04:00">INTERIM</status_change>
            <status_change date="2014-10-27T04:00:23.609-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
        <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
          <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
          <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
          <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
          <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
          <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
        </criteria>
        <criteria operator="OR" comment="Check for vulnerable versions">
          <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17088" test_ref="oval:org.mitre.oval:tst:123567"/>
          <criteria operator="AND" comment="Check for LDR">
            <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21207" test_ref="oval:org.mitre.oval:tst:123452"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:25997" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability - CVE-2014-2820 (MS14-051)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-2820" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2820"/>
        <description>Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-2774, CVE-2014-2826, CVE-2014-2827, and CVE-2014-4063.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-08-19T08:33:30">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-08-26T16:08:08.185-04:00">DRAFT</status_change>
            <status_change date="2014-09-15T04:00:26.792-04:00">INTERIM</status_change>
            <status_change date="2014-10-06T04:03:20.474-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5392" test_ref="oval:org.mitre.oval:tst:121772"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21397" test_ref="oval:org.mitre.oval:tst:121743"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista/2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19143" test_ref="oval:org.mitre.oval:tst:122338"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23446" test_ref="oval:org.mitre.oval:tst:122105"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23611" test_ref="oval:org.mitre.oval:tst:122198"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19553" test_ref="oval:org.mitre.oval:tst:122307"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23611" test_ref="oval:org.mitre.oval:tst:122198"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18534" test_ref="oval:org.mitre.oval:tst:122429"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22745" test_ref="oval:org.mitre.oval:tst:122320"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16563" test_ref="oval:org.mitre.oval:tst:122010"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20674" test_ref="oval:org.mitre.oval:tst:121838"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17054" test_ref="oval:org.mitre.oval:tst:121473"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21173" test_ref="oval:org.mitre.oval:tst:122251"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7 / 2k8 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17239" test_ref="oval:org.mitre.oval:tst:122281"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:25962" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability - CVE-2014-2808 (MS14-051)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-2808" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2808"/>
        <description>Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-2796, CVE-2014-2825, CVE-2014-4050, CVE-2014-4055, and CVE-2014-4067.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-08-19T08:33:30">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-08-26T16:07:37.512-04:00">DRAFT</status_change>
            <status_change date="2014-09-15T04:00:25.896-04:00">INTERIM</status_change>
            <status_change date="2014-10-06T04:03:20.142-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17054" test_ref="oval:org.mitre.oval:tst:121473"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21173" test_ref="oval:org.mitre.oval:tst:122251"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7 / 2k8 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17239" test_ref="oval:org.mitre.oval:tst:122281"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:25633" version="5" class="vulnerability">
      <metadata>
        <title>Arbitrary code executing via unknown vectors.</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 8</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2011-1346" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1346"/>
        <description>Unspecified vulnerability in Microsoft Internet Explorer 8 on Windows 7 allows remote attackers to execute arbitrary code via unknown vectors, as demonstrated by Stephen Fewer as the second of three chained vulnerabilities during a Pwn2Own competition at CanSecWest 2011.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-09-03T08:31:03">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </submitted>
            <status_change date="2014-09-11T08:03:36.855-04:00">DRAFT</status_change>
            <status_change date="2014-09-29T04:00:12.433-04:00">INTERIM</status_change>
            <status_change date="2014-10-20T04:00:13.514-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:25633 - Modified vulnerabilities - a lot of fixes" date="2015-07-22T13:39:00.268-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-07-22T13:41:44.917-04:00">INTERIM</status_change>
            <status_change date="2015-08-10T04:00:25.583-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
        <criteria operator="OR" comment="GDR or LDR Service branch">
          <criterion comment="Mshtml.dll version is less than 8.0.7600.16722" test_ref="oval:org.mitre.oval:tst:42403"/>
          <criteria operator="AND" comment="LDR">
            <criterion comment="Mshtml.dll version is greater than or equal 8.0.7600.20000" test_ref="oval:org.mitre.oval:tst:20848"/>
            <criterion comment="Mshtml.dll version is less than 8.0.7600.20861" test_ref="oval:org.mitre.oval:tst:42393"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:25219" version="6" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability - CVE-2014-2801 (MS14-037)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-2801" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2801"/>
        <description>Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-07-11T08:33:30">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-07-11T11:47:52.709-04:00">DRAFT</status_change>
            <status_change date="2014-07-28T04:00:53.114-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:25219 - Updated to remove SP checks." date="2014-08-07T14:56:00.647-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-08-25T04:00:59.097-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17028" test_ref="oval:org.mitre.oval:tst:115430"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21145" test_ref="oval:org.mitre.oval:tst:115571"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16672" test_ref="oval:org.mitre.oval:tst:115696"/>
                <criteria operator="AND" comment="kb2957689 and kb2929437">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 11.0.9600.17041" test_ref="oval:org.mitre.oval:tst:113778"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17207" test_ref="oval:org.mitre.oval:tst:115689"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 8.1 / 2k12 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16672" test_ref="oval:org.mitre.oval:tst:115696"/>
                <criteria operator="AND" comment="kb2957689 and kb2919355">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 11.0.9600.17037" test_ref="oval:org.mitre.oval:tst:114108"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17207" test_ref="oval:org.mitre.oval:tst:115689"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:25213" version="5" class="vulnerability">
      <metadata>
        <title>Win32k Elevation of Privilege Vulnerability - CVE-2014-2781 (MS14-039)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Vista</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-2781" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2781"/>
        <description>Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 do not properly restrict the exchange of keyboard and mouse data between programs at different integrity levels, which allows attackers to bypass intended access restrictions by leveraging control over a low-integrity process to launch the On-Screen Keyboard (OSK) and then upload a crafted application, aka "On-Screen Keyboard Elevation of Privilege Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-07-11T08:40:43">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-07-11T11:50:34.190-04:00">DRAFT</status_change>
            <status_change date="2014-07-28T04:00:52.952-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:03:30.129-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vista / 2k8 + vulnerable file version">
          <criteria operator="OR" comment="Vista / 2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
            <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of win32k.sys is less than 6.0.6002.19119" test_ref="oval:org.mitre.oval:tst:115705"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:81723"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.0.6002.23420" test_ref="oval:org.mitre.oval:tst:115407"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / R2 + vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12292"/>
            <extend_definition comment="Microsoft Windows 7 x64 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12627"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12567"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12583"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.18512" test_ref="oval:org.mitre.oval:tst:115070"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:81763"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.22722" test_ref="oval:org.mitre.oval:tst:115618"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8/2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.17025" test_ref="oval:org.mitre.oval:tst:115552"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:115678"/>
              <criterion comment="Check if the version of Win32k.sys is less than 6.2.9200.21142" test_ref="oval:org.mitre.oval:tst:115273"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1 / 2K12 R2and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criteria operator="OR" comment="Check for with update and without update">
            <criterion comment="Check if the version of win32k.sys is less than 6.3.9600.16671" test_ref="oval:org.mitre.oval:tst:115570"/>
            <criteria operator="AND" comment="kb2973201 and kb2919355">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.3.9600.17031" test_ref="oval:org.mitre.oval:tst:115567"/>
              <criterion comment="Check if the version of Win32k.sys is less than 6.3.9600.17200" test_ref="oval:org.mitre.oval:tst:115441"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:25207" version="6" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability - CVE-2014-2800 (MS14-037)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-2800" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2800"/>
        <description>Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-2807 and CVE-2014-2809.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-07-11T08:33:30">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-07-11T11:47:14.917-04:00">DRAFT</status_change>
            <status_change date="2014-07-28T04:00:52.441-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:25207 - Updated to remove SP checks." date="2014-08-07T14:56:00.647-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-08-25T04:00:58.369-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5358" test_ref="oval:org.mitre.oval:tst:115411"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21395" test_ref="oval:org.mitre.oval:tst:115023"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista/2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19114" test_ref="oval:org.mitre.oval:tst:114740"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23413" test_ref="oval:org.mitre.oval:tst:115693"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23603" test_ref="oval:org.mitre.oval:tst:115559"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19543" test_ref="oval:org.mitre.oval:tst:114962"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23603" test_ref="oval:org.mitre.oval:tst:115559"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18487" test_ref="oval:org.mitre.oval:tst:115377"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22703" test_ref="oval:org.mitre.oval:tst:115320"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16561" test_ref="oval:org.mitre.oval:tst:114824"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20672" test_ref="oval:org.mitre.oval:tst:115308"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17028" test_ref="oval:org.mitre.oval:tst:115430"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21145" test_ref="oval:org.mitre.oval:tst:115571"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16672" test_ref="oval:org.mitre.oval:tst:115696"/>
                <criteria operator="AND" comment="kb2957689 and kb2929437">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 11.0.9600.17041" test_ref="oval:org.mitre.oval:tst:113778"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17207" test_ref="oval:org.mitre.oval:tst:115689"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 8.1 / 2k12 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16672" test_ref="oval:org.mitre.oval:tst:115696"/>
                <criteria operator="AND" comment="kb2957689 and kb2919355">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 11.0.9600.17037" test_ref="oval:org.mitre.oval:tst:114108"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17207" test_ref="oval:org.mitre.oval:tst:115689"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:25190" version="6" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability - CVE-2014-2786 (MS14-037)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-2786" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2786"/>
        <description>Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-2792 and CVE-2014-2813.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-07-11T08:33:30">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-07-11T11:47:54.466-04:00">DRAFT</status_change>
            <status_change date="2014-07-28T04:00:52.043-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:25190 - Updated to remove SP checks." date="2014-08-07T14:56:00.647-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-08-25T04:00:57.946-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16561" test_ref="oval:org.mitre.oval:tst:114824"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20672" test_ref="oval:org.mitre.oval:tst:115308"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17028" test_ref="oval:org.mitre.oval:tst:115430"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21145" test_ref="oval:org.mitre.oval:tst:115571"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16672" test_ref="oval:org.mitre.oval:tst:115696"/>
                <criteria operator="AND" comment="kb2957689 and kb2929437">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 11.0.9600.17041" test_ref="oval:org.mitre.oval:tst:113778"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17207" test_ref="oval:org.mitre.oval:tst:115689"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 8.1 / 2k12 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16672" test_ref="oval:org.mitre.oval:tst:115696"/>
                <criteria operator="AND" comment="kb2957689 and kb2919355">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 11.0.9600.17037" test_ref="oval:org.mitre.oval:tst:114108"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17207" test_ref="oval:org.mitre.oval:tst:115689"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:25182" version="6" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability - CVE-2014-2807 (MS14-037)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-2807" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2807"/>
        <description>Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-2800 and CVE-2014-2809.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-07-11T08:33:30">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-07-11T11:48:00.406-04:00">DRAFT</status_change>
            <status_change date="2014-07-28T04:00:51.671-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:25182 - Updated to remove SP checks." date="2014-08-07T14:56:00.647-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-08-25T04:00:57.438-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5358" test_ref="oval:org.mitre.oval:tst:115411"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21395" test_ref="oval:org.mitre.oval:tst:115023"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista/2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19114" test_ref="oval:org.mitre.oval:tst:114740"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23413" test_ref="oval:org.mitre.oval:tst:115693"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23603" test_ref="oval:org.mitre.oval:tst:115559"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19543" test_ref="oval:org.mitre.oval:tst:114962"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23603" test_ref="oval:org.mitre.oval:tst:115559"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18487" test_ref="oval:org.mitre.oval:tst:115377"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22703" test_ref="oval:org.mitre.oval:tst:115320"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16561" test_ref="oval:org.mitre.oval:tst:114824"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20672" test_ref="oval:org.mitre.oval:tst:115308"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17028" test_ref="oval:org.mitre.oval:tst:115430"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21145" test_ref="oval:org.mitre.oval:tst:115571"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16672" test_ref="oval:org.mitre.oval:tst:115696"/>
                <criteria operator="AND" comment="kb2957689 and kb2929437">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 11.0.9600.17041" test_ref="oval:org.mitre.oval:tst:113778"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17207" test_ref="oval:org.mitre.oval:tst:115689"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 8.1 / 2k12 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16672" test_ref="oval:org.mitre.oval:tst:115696"/>
                <criteria operator="AND" comment="kb2957689 and kb2919355">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 11.0.9600.17037" test_ref="oval:org.mitre.oval:tst:114108"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17207" test_ref="oval:org.mitre.oval:tst:115689"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:25143" version="6" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability - CVE-2014-2804 (MS14-037)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-2804" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2804"/>
        <description>Microsoft Internet Explorer 8 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-2789, CVE-2014-2795, and CVE-2014-2798.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-07-11T08:33:30">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-07-11T11:47:50.184-04:00">DRAFT</status_change>
            <status_change date="2014-07-28T04:00:50.965-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:25143 - Updated to remove SP checks." date="2014-08-07T14:56:00.647-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-08-25T04:00:54.609-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23603" test_ref="oval:org.mitre.oval:tst:115559"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19543" test_ref="oval:org.mitre.oval:tst:114962"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23603" test_ref="oval:org.mitre.oval:tst:115559"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18487" test_ref="oval:org.mitre.oval:tst:115377"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22703" test_ref="oval:org.mitre.oval:tst:115320"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16561" test_ref="oval:org.mitre.oval:tst:114824"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20672" test_ref="oval:org.mitre.oval:tst:115308"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17028" test_ref="oval:org.mitre.oval:tst:115430"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21145" test_ref="oval:org.mitre.oval:tst:115571"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16672" test_ref="oval:org.mitre.oval:tst:115696"/>
                <criteria operator="AND" comment="kb2957689 and kb2929437">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 11.0.9600.17041" test_ref="oval:org.mitre.oval:tst:113778"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17207" test_ref="oval:org.mitre.oval:tst:115689"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 8.1 / 2k12 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16672" test_ref="oval:org.mitre.oval:tst:115696"/>
                <criteria operator="AND" comment="kb2957689 and kb2919355">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 11.0.9600.17037" test_ref="oval:org.mitre.oval:tst:114108"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17207" test_ref="oval:org.mitre.oval:tst:115689"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:25112" version="5" class="vulnerability">
      <metadata>
        <title>DirectShow Elevation of Privilege Vulnerability - CVE-2014-2780 (MS14-041)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-2780" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2780"/>
        <description>DirectShow in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 allows local users to gain privileges by leveraging control over a low-integrity process to execute a crafted application, aka "DirectShow Elevation of Privilege Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-07-11T12:04:24">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-07-11T11:53:04.839-04:00">DRAFT</status_change>
            <status_change date="2014-07-28T04:00:49.397-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:03:15.727-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vista/2K8 and vulnerable file version">
          <criteria operator="OR" comment="Vista / 2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of qedit.dll is less than 6.6.6002.19118" test_ref="oval:org.mitre.oval:tst:115438"/>
            <criteria operator="AND" comment="Check for LDR range">
              <criterion comment="Check if the version of qedit.dll is greater than or equal to 6.6.6002.23000" test_ref="oval:org.mitre.oval:tst:81807"/>
              <criterion comment="Check if the version of qedit.dll is less than 6.6.6002.23418" test_ref="oval:org.mitre.oval:tst:115437"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / R2 and vulnerable version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12292"/>
            <extend_definition comment="Microsoft Windows 7 x64 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12627"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12567"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of qedit.dll is less than 6.6.7601.18501" test_ref="oval:org.mitre.oval:tst:115716"/>
            <criteria operator="AND" comment="Check for LDR range">
              <criterion comment="Check if the version of qedit.dll is greater than or equal to 6.6.7601.22000" test_ref="oval:org.mitre.oval:tst:81771"/>
              <criterion comment="Check if the version of qedit.dll is less than 6.6.7601.22716" test_ref="oval:org.mitre.oval:tst:115674"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8 / 2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of qedit.dll is less than 6.6.9200.17023" test_ref="oval:org.mitre.oval:tst:115629"/>
            <criteria operator="AND" comment="Check for LDR range">
              <criterion comment="Check if the version of qedit.dll is greater than or equal to 6.6.9200.20000" test_ref="oval:org.mitre.oval:tst:81492"/>
              <criterion comment="Check if the version of qedit.dll is less than 6.6.9200.21140" test_ref="oval:org.mitre.oval:tst:115619"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="8.1/2012 R2 and vulnerable version">
          <criteria operator="OR" comment="8.1/2012 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
          </criteria>
          <criteria operator="OR" comment="vulnerable version">
            <criteria operator="AND" comment="kb2972280 and kb2919355">
              <criterion comment="Check if the version of qedit.dll is less than 6.6.9600.17200" test_ref="oval:org.mitre.oval:tst:115516"/>
              <criterion comment="Check if the version of qedit.dll is greater than or equal to 6.6.9600.17031" test_ref="oval:org.mitre.oval:tst:115712"/>
            </criteria>
            <criterion comment="Check if the version of qedit.dll is less than 6.6.9600.16672" test_ref="oval:org.mitre.oval:tst:115285"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:25105" version="6" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability - CVE-2014-2803 (MS14-037)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-2803" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2803"/>
        <description>Microsoft Internet Explorer 8 through 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-07-11T08:33:30">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-07-11T11:47:45.037-04:00">DRAFT</status_change>
            <status_change date="2014-07-28T04:00:48.984-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:25105 - Updated to remove SP checks." date="2014-08-07T14:56:00.647-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-08-25T04:00:54.239-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23603" test_ref="oval:org.mitre.oval:tst:115559"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19543" test_ref="oval:org.mitre.oval:tst:114962"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23603" test_ref="oval:org.mitre.oval:tst:115559"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18487" test_ref="oval:org.mitre.oval:tst:115377"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22703" test_ref="oval:org.mitre.oval:tst:115320"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16561" test_ref="oval:org.mitre.oval:tst:114824"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20672" test_ref="oval:org.mitre.oval:tst:115308"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17028" test_ref="oval:org.mitre.oval:tst:115430"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21145" test_ref="oval:org.mitre.oval:tst:115571"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:25096" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability - CVE-2014-1765 (MS14-037)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-1765" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1765"/>
        <description>Multiple use-after-free vulnerabilities in Microsoft Internet Explorer 6 through 11 allow remote attackers to execute arbitrary code via unspecified vectors, as demonstrated by Sebastian Apelt and Andreas Schmidt during a Pwn2Own competition at CanSecWest 2014.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-07-11T08:33:30">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-07-11T11:47:42.536-04:00">DRAFT</status_change>
            <status_change date="2014-07-28T04:00:48.622-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:25096 - Updated to remove SP checks." date="2014-08-07T14:56:00.647-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-08-25T04:00:53.618-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5358" test_ref="oval:org.mitre.oval:tst:115411"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21395" test_ref="oval:org.mitre.oval:tst:115023"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista/2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19114" test_ref="oval:org.mitre.oval:tst:114740"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23413" test_ref="oval:org.mitre.oval:tst:115693"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23603" test_ref="oval:org.mitre.oval:tst:115559"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19543" test_ref="oval:org.mitre.oval:tst:114962"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23603" test_ref="oval:org.mitre.oval:tst:115559"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18487" test_ref="oval:org.mitre.oval:tst:115377"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22703" test_ref="oval:org.mitre.oval:tst:115320"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16561" test_ref="oval:org.mitre.oval:tst:114824"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20672" test_ref="oval:org.mitre.oval:tst:115308"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17028" test_ref="oval:org.mitre.oval:tst:115430"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21145" test_ref="oval:org.mitre.oval:tst:115571"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16672" test_ref="oval:org.mitre.oval:tst:115696"/>
                <criteria operator="AND" comment="kb2957689 and kb2929437">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 11.0.9600.17041" test_ref="oval:org.mitre.oval:tst:113778"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17207" test_ref="oval:org.mitre.oval:tst:115689"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 8.1 / 2k12 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16672" test_ref="oval:org.mitre.oval:tst:115696"/>
                <criteria operator="AND" comment="kb2957689 and kb2919355">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 11.0.9600.17037" test_ref="oval:org.mitre.oval:tst:114108"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17207" test_ref="oval:org.mitre.oval:tst:115689"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:25034" version="6" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability - CVE-2014-2809 (MS14-037)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-2809" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2809"/>
        <description>Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-2800 and CVE-2014-2807.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-07-11T08:33:30">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-07-11T11:47:28.449-04:00">DRAFT</status_change>
            <status_change date="2014-07-28T04:00:47.544-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:25034 - Updated to remove SP checks." date="2014-08-07T14:56:00.647-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-08-25T04:00:52.413-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5358" test_ref="oval:org.mitre.oval:tst:115411"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21395" test_ref="oval:org.mitre.oval:tst:115023"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista/2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19114" test_ref="oval:org.mitre.oval:tst:114740"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23413" test_ref="oval:org.mitre.oval:tst:115693"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23603" test_ref="oval:org.mitre.oval:tst:115559"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19543" test_ref="oval:org.mitre.oval:tst:114962"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23603" test_ref="oval:org.mitre.oval:tst:115559"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18487" test_ref="oval:org.mitre.oval:tst:115377"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22703" test_ref="oval:org.mitre.oval:tst:115320"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16561" test_ref="oval:org.mitre.oval:tst:114824"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20672" test_ref="oval:org.mitre.oval:tst:115308"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17028" test_ref="oval:org.mitre.oval:tst:115430"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21145" test_ref="oval:org.mitre.oval:tst:115571"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16672" test_ref="oval:org.mitre.oval:tst:115696"/>
                <criteria operator="AND" comment="kb2957689 and kb2929437">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 11.0.9600.17041" test_ref="oval:org.mitre.oval:tst:113778"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17207" test_ref="oval:org.mitre.oval:tst:115689"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 8.1 / 2k12 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16672" test_ref="oval:org.mitre.oval:tst:115696"/>
                <criteria operator="AND" comment="kb2957689 and kb2919355">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 11.0.9600.17037" test_ref="oval:org.mitre.oval:tst:114108"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17207" test_ref="oval:org.mitre.oval:tst:115689"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:25024" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability (CVE-2014-1805) - MS14-035</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-1805" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1805"/>
        <description>Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-1773, CVE-2014-1783, CVE-2014-1784, CVE-2014-1786, CVE-2014-1795, CVE-2014-2758, CVE-2014-2759, CVE-2014-2765, CVE-2014-2766, and CVE-2014-2775.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-06-16T09:23:20">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-06-20T11:22:40.378-04:00">DRAFT</status_change>
            <status_change date="2014-07-07T04:01:33.444-04:00">INTERIM</status_change>
            <status_change date="2014-07-28T04:00:47.058-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:25024 - Updated to remove SP checks." date="2014-08-07T14:55:00.409-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-08-07T14:56:55.111-04:00">INTERIM</status_change>
            <status_change date="2014-08-25T04:00:52.029-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16555" test_ref="oval:org.mitre.oval:tst:114960"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20666" test_ref="oval:org.mitre.oval:tst:114734"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16921" test_ref="oval:org.mitre.oval:tst:114739"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21044" test_ref="oval:org.mitre.oval:tst:114922"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16668" test_ref="oval:org.mitre.oval:tst:114145"/>
                <criteria operator="AND" comment="kb2957689 and kb2929437">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 11.0.9600.17041" test_ref="oval:org.mitre.oval:tst:113778"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17126" test_ref="oval:org.mitre.oval:tst:113991"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 8.1 / 2k12 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16668" test_ref="oval:org.mitre.oval:tst:114145"/>
                <criteria operator="AND" comment="kb2957689 and kb2919355">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 11.0.9600.17037" test_ref="oval:org.mitre.oval:tst:114108"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17126" test_ref="oval:org.mitre.oval:tst:113991"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:25012" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability - CVE-2014-1763 (MS14-037)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-1763" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1763"/>
        <description>Use-after-free vulnerability in Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code and bypass a sandbox protection mechanism via unspecified vectors, as demonstrated by VUPEN during a Pwn2Own competition at CanSecWest 2014.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-07-11T08:33:30">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-07-11T11:47:16.755-04:00">DRAFT</status_change>
            <status_change date="2014-07-28T04:00:46.638-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:25012 - Updated to remove SP checks." date="2014-08-07T14:56:00.647-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-08-25T04:00:51.545-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16561" test_ref="oval:org.mitre.oval:tst:114824"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20672" test_ref="oval:org.mitre.oval:tst:115308"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17028" test_ref="oval:org.mitre.oval:tst:115430"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21145" test_ref="oval:org.mitre.oval:tst:115571"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16672" test_ref="oval:org.mitre.oval:tst:115696"/>
                <criteria operator="AND" comment="kb2957689 and kb2929437">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 11.0.9600.17041" test_ref="oval:org.mitre.oval:tst:113778"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17207" test_ref="oval:org.mitre.oval:tst:115689"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 8.1 / 2k12 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16672" test_ref="oval:org.mitre.oval:tst:115696"/>
                <criteria operator="AND" comment="kb2957689 and kb2919355">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 11.0.9600.17037" test_ref="oval:org.mitre.oval:tst:114108"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17207" test_ref="oval:org.mitre.oval:tst:115689"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24991" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability (CVE-2014-2758) - MS14-035</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-2758" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2758"/>
        <description>Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-1773, CVE-2014-1783, CVE-2014-1784, CVE-2014-1786, CVE-2014-1795, CVE-2014-1805, CVE-2014-2759, CVE-2014-2765, CVE-2014-2766, and CVE-2014-2775.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-06-16T09:23:20">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-06-20T11:22:12.077-04:00">DRAFT</status_change>
            <status_change date="2014-07-07T04:01:32.682-04:00">INTERIM</status_change>
            <status_change date="2014-07-28T04:00:45.996-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24991 - Updated to remove SP checks." date="2014-08-07T14:55:00.409-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-08-07T14:56:55.525-04:00">INTERIM</status_change>
            <status_change date="2014-08-25T04:00:50.614-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16555" test_ref="oval:org.mitre.oval:tst:114960"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20666" test_ref="oval:org.mitre.oval:tst:114734"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16921" test_ref="oval:org.mitre.oval:tst:114739"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21044" test_ref="oval:org.mitre.oval:tst:114922"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16668" test_ref="oval:org.mitre.oval:tst:114145"/>
                <criteria operator="AND" comment="kb2957689 and kb2929437">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 11.0.9600.17041" test_ref="oval:org.mitre.oval:tst:113778"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17126" test_ref="oval:org.mitre.oval:tst:113991"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 8.1 / 2k12 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16668" test_ref="oval:org.mitre.oval:tst:114145"/>
                <criteria operator="AND" comment="kb2957689 and kb2919355">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 11.0.9600.17037" test_ref="oval:org.mitre.oval:tst:114108"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17126" test_ref="oval:org.mitre.oval:tst:113991"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24990" version="6" class="vulnerability">
      <metadata>
        <title>Extended Validation (EV) Certificate Security Feature Bypass Vulnerability - CVE-2014-2783 (MS14-037)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-2783" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2783"/>
        <description>Microsoft Internet Explorer 7 through 11 does not prevent use of wildcard EV SSL certificates, which might allow remote attackers to spoof a trust level by leveraging improper issuance of a wildcard certificate by a recognized Certification Authority, aka "Extended Validation (EV) Certificate Security Feature Bypass Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-07-11T08:33:30">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-07-11T11:47:33.936-04:00">DRAFT</status_change>
            <status_change date="2014-07-28T04:00:45.703-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24990 - Updated to remove SP checks." date="2014-08-07T14:56:00.647-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-08-25T04:00:50.140-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21395" test_ref="oval:org.mitre.oval:tst:115023"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista/2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19114" test_ref="oval:org.mitre.oval:tst:114740"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23413" test_ref="oval:org.mitre.oval:tst:115693"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23603" test_ref="oval:org.mitre.oval:tst:115559"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19543" test_ref="oval:org.mitre.oval:tst:114962"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23603" test_ref="oval:org.mitre.oval:tst:115559"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18487" test_ref="oval:org.mitre.oval:tst:115377"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22703" test_ref="oval:org.mitre.oval:tst:115320"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16561" test_ref="oval:org.mitre.oval:tst:114824"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20672" test_ref="oval:org.mitre.oval:tst:115308"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17028" test_ref="oval:org.mitre.oval:tst:115430"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21145" test_ref="oval:org.mitre.oval:tst:115571"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16672" test_ref="oval:org.mitre.oval:tst:115696"/>
                <criteria operator="AND" comment="kb2957689 and kb2929437">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 11.0.9600.17041" test_ref="oval:org.mitre.oval:tst:113778"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17207" test_ref="oval:org.mitre.oval:tst:115689"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 8.1 / 2k12 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16672" test_ref="oval:org.mitre.oval:tst:115696"/>
                <criteria operator="AND" comment="kb2957689 and kb2919355">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 11.0.9600.17037" test_ref="oval:org.mitre.oval:tst:114108"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17207" test_ref="oval:org.mitre.oval:tst:115689"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24986" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability (CVE-2014-1772) - MS14-035</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-1772" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1772"/>
        <description>Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-1780, CVE-2014-1794, CVE-2014-1797, CVE-2014-1802, CVE-2014-2756, CVE-2014-2763, CVE-2014-2764, CVE-2014-2769, and CVE-2014-2771.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-06-16T09:23:20">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-06-20T11:22:57.437-04:00">DRAFT</status_change>
            <status_change date="2014-07-07T04:01:32.461-04:00">INTERIM</status_change>
            <status_change date="2014-07-28T04:00:45.369-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24986 - Updated to remove SP checks." date="2014-08-07T14:51:00.976-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-08-07T14:55:15.739-04:00">INTERIM</status_change>
            <status_change date="2014-08-25T04:00:49.775-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16921" test_ref="oval:org.mitre.oval:tst:114739"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21044" test_ref="oval:org.mitre.oval:tst:114922"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16668" test_ref="oval:org.mitre.oval:tst:114145"/>
                <criteria operator="AND" comment="kb2957689 and kb2929437">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 11.0.9600.17041" test_ref="oval:org.mitre.oval:tst:113778"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17126" test_ref="oval:org.mitre.oval:tst:113991"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 8.1 / 2k12 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16668" test_ref="oval:org.mitre.oval:tst:114145"/>
                <criteria operator="AND" comment="kb2957689 and kb2919355">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 11.0.9600.17037" test_ref="oval:org.mitre.oval:tst:114108"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17126" test_ref="oval:org.mitre.oval:tst:113991"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24976" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability (CVE-2014-1766) - MS14-035</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-1766" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1766"/>
        <description>Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, as demonstrated by Sebastian Apelt and Andreas Schmidt during a Pwn2Own competition at CanSecWest 2014. NOTE: the original disclosure referred to triggering a kernel bug with the Internet Explorer exploit payload, but this ID is not for a kernel vulnerability.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-06-16T09:23:20">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-06-20T11:22:14.721-04:00">DRAFT</status_change>
            <status_change date="2014-07-07T04:01:32.109-04:00">INTERIM</status_change>
            <status_change date="2014-07-28T04:00:44.956-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24976 - Updated to remove SP checks." date="2014-08-07T14:51:00.976-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-08-07T14:55:11.078-04:00">INTERIM</status_change>
            <status_change date="2014-08-25T04:00:49.430-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16555" test_ref="oval:org.mitre.oval:tst:114960"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20666" test_ref="oval:org.mitre.oval:tst:114734"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16921" test_ref="oval:org.mitre.oval:tst:114739"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21044" test_ref="oval:org.mitre.oval:tst:114922"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16668" test_ref="oval:org.mitre.oval:tst:114145"/>
                <criteria operator="AND" comment="kb2957689 and kb2929437">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 11.0.9600.17041" test_ref="oval:org.mitre.oval:tst:113778"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17126" test_ref="oval:org.mitre.oval:tst:113991"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 8.1 / 2k12 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16668" test_ref="oval:org.mitre.oval:tst:114145"/>
                <criteria operator="AND" comment="kb2957689 and kb2919355">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 11.0.9600.17037" test_ref="oval:org.mitre.oval:tst:114108"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17126" test_ref="oval:org.mitre.oval:tst:113991"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24974" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer Information Disclosure Vulnerability (CVE-2014-1777) - MS14-035</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-1777" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1777"/>
        <description>Microsoft Internet Explorer 10 and 11 allows remote attackers to read local files on the client via a crafted web site, aka "Internet Explorer Information Disclosure Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-06-16T09:23:20">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-06-20T11:21:40.789-04:00">DRAFT</status_change>
            <status_change date="2014-07-07T04:01:31.743-04:00">INTERIM</status_change>
            <status_change date="2014-07-28T04:00:44.588-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24974 - Updated to remove SP checks." date="2014-08-07T14:51:00.976-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-08-07T14:55:10.373-04:00">INTERIM</status_change>
            <status_change date="2014-08-25T04:00:48.904-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16921" test_ref="oval:org.mitre.oval:tst:114739"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21044" test_ref="oval:org.mitre.oval:tst:114922"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16668" test_ref="oval:org.mitre.oval:tst:114145"/>
                <criteria operator="AND" comment="kb2957689 and kb2929437">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 11.0.9600.17041" test_ref="oval:org.mitre.oval:tst:113778"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17126" test_ref="oval:org.mitre.oval:tst:113991"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 8.1 / 2k12 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16668" test_ref="oval:org.mitre.oval:tst:114145"/>
                <criteria operator="AND" comment="kb2957689 and kb2919355">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 11.0.9600.17037" test_ref="oval:org.mitre.oval:tst:114108"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17126" test_ref="oval:org.mitre.oval:tst:113991"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24972" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability (CVE-2014-2771) - MS14-035</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-2771" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2771"/>
        <description>Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-1772, CVE-2014-1780, CVE-2014-1794, CVE-2014-1797, CVE-2014-1802, CVE-2014-2756, CVE-2014-2763, CVE-2014-2764, and CVE-2014-2769.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-06-16T09:23:20">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-06-20T11:22:42.555-04:00">DRAFT</status_change>
            <status_change date="2014-07-07T04:01:31.564-04:00">INTERIM</status_change>
            <status_change date="2014-07-28T04:00:44.221-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24972 - Updated to remove SP checks." date="2014-08-07T14:51:00.976-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-08-07T14:55:10.152-04:00">INTERIM</status_change>
            <status_change date="2014-08-25T04:00:48.609-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16921" test_ref="oval:org.mitre.oval:tst:114739"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21044" test_ref="oval:org.mitre.oval:tst:114922"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16668" test_ref="oval:org.mitre.oval:tst:114145"/>
                <criteria operator="AND" comment="kb2957689 and kb2929437">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 11.0.9600.17041" test_ref="oval:org.mitre.oval:tst:113778"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17126" test_ref="oval:org.mitre.oval:tst:113991"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 8.1 / 2k12 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16668" test_ref="oval:org.mitre.oval:tst:114145"/>
                <criteria operator="AND" comment="kb2957689 and kb2919355">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 11.0.9600.17037" test_ref="oval:org.mitre.oval:tst:114108"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17126" test_ref="oval:org.mitre.oval:tst:113991"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24967" version="6" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability - CVE-2014-2813 (MS14-037)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-2813" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2813"/>
        <description>Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-2786 and CVE-2014-2792.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-07-11T08:33:30">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-07-11T11:47:23.313-04:00">DRAFT</status_change>
            <status_change date="2014-07-28T04:00:43.813-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24967 - Updated to remove SP checks." date="2014-08-07T14:56:00.647-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-08-25T04:00:48.259-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16561" test_ref="oval:org.mitre.oval:tst:114824"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20672" test_ref="oval:org.mitre.oval:tst:115308"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17028" test_ref="oval:org.mitre.oval:tst:115430"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21145" test_ref="oval:org.mitre.oval:tst:115571"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16672" test_ref="oval:org.mitre.oval:tst:115696"/>
                <criteria operator="AND" comment="kb2957689 and kb2929437">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 11.0.9600.17041" test_ref="oval:org.mitre.oval:tst:113778"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17207" test_ref="oval:org.mitre.oval:tst:115689"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 8.1 / 2k12 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16672" test_ref="oval:org.mitre.oval:tst:115696"/>
                <criteria operator="AND" comment="kb2957689 and kb2919355">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 11.0.9600.17037" test_ref="oval:org.mitre.oval:tst:114108"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17207" test_ref="oval:org.mitre.oval:tst:115689"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24965" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer Elevation of Privilege Vulnerability (CVE-2014-1764) - MS14-035</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-1764" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1764"/>
        <description>Microsoft Internet Explorer 7 through 11 allows remote attackers to execute arbitrary code and bypass a sandbox protection mechanism by leveraging "object confusion" in a broker process, as demonstrated by VUPEN during a Pwn2Own competition at CanSecWest 2014.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-06-16T09:23:20">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-06-20T11:21:39.440-04:00">DRAFT</status_change>
            <status_change date="2014-07-07T04:01:31.098-04:00">INTERIM</status_change>
            <status_change date="2014-07-28T04:00:43.560-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24965 - Updated to remove SP checks." date="2014-08-07T14:51:00.976-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-08-07T14:55:10.727-04:00">INTERIM</status_change>
            <status_change date="2014-08-25T04:00:47.738-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21389" test_ref="oval:org.mitre.oval:tst:114956"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista/2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19098" test_ref="oval:org.mitre.oval:tst:114438"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23389" test_ref="oval:org.mitre.oval:tst:114853"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23598" test_ref="oval:org.mitre.oval:tst:114669"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19539" test_ref="oval:org.mitre.oval:tst:114916"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23598" test_ref="oval:org.mitre.oval:tst:114669"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18472" test_ref="oval:org.mitre.oval:tst:114770"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22686" test_ref="oval:org.mitre.oval:tst:114915"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16555" test_ref="oval:org.mitre.oval:tst:114960"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20666" test_ref="oval:org.mitre.oval:tst:114734"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16921" test_ref="oval:org.mitre.oval:tst:114739"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21044" test_ref="oval:org.mitre.oval:tst:114922"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16668" test_ref="oval:org.mitre.oval:tst:114145"/>
                <criteria operator="AND" comment="kb2957689 and kb2929437">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 11.0.9600.17041" test_ref="oval:org.mitre.oval:tst:113778"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17126" test_ref="oval:org.mitre.oval:tst:113991"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 8.1 / 2k12 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16668" test_ref="oval:org.mitre.oval:tst:114145"/>
                <criteria operator="AND" comment="kb2957689 and kb2919355">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 11.0.9600.17037" test_ref="oval:org.mitre.oval:tst:114108"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17126" test_ref="oval:org.mitre.oval:tst:113991"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24963" version="6" class="vulnerability">
      <metadata>
        <title>Vulnerability in Microsoft XML Core Services could allow information disclosure (CVE-2014-1816) - MS14-033</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft XML Core Services 3</product>
          <product>Microsoft XML Core Services 6</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-1816" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1816"/>
        <description>Microsoft XML Core Services (aka MSXML) 3.0 and 6.0 does not properly restrict the information transmitted by Internet Explorer during a download action, which allows remote attackers to discover (1) full pathnames on the client system and (2) local usernames embedded in these pathnames via a crafted web site, aka "MSXML Entity URI Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-06-16T09:35:14">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-06-20T11:04:13.279-04:00">DRAFT</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:19706 - comment has been updated from &quot;less than&quot; to &quot;greater than or equal&quot;" date="2014-06-20T11:02:00.031-04:00">
              <contributor organization="SecPod Technologies">Saurabh Kumar</contributor>
            </modified>
            <status_change date="2014-07-07T04:01:30.809-04:00">INTERIM</status_change>
            <status_change date="2014-07-28T04:00:42.877-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24963 - Updated to remove SP checks." date="2014-08-07T14:51:00.976-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-08-07T14:55:16.608-04:00">INTERIM</status_change>
            <status_change date="2014-08-25T04:00:47.077-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="2003/version">
          <extend_definition comment="Microsoft XML Core Services 3 is installed" definition_ref="oval:org.mitre.oval:def:415"/>
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of Msxml3.dll is less than 8.100.1055.0" test_ref="oval:org.mitre.oval:tst:114554"/>
        </criteria>
        <criteria operator="AND" comment="2003/version">
          <extend_definition comment="Microsoft XML Core Services 6 is installed" definition_ref="oval:org.mitre.oval:def:454"/>
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of Msxml6.dll is less than 6.20.2017.0" test_ref="oval:org.mitre.oval:tst:114851"/>
        </criteria>
        <criteria operator="AND" comment="vista/2008/versions/Core services 3.0">
          <extend_definition comment="Microsoft XML Core Services 3 is installed" definition_ref="oval:org.mitre.oval:def:415"/>
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criterion comment="Check if the version of Msxml3.dll is less than 8.100.5008.0" test_ref="oval:org.mitre.oval:tst:114914"/>
        </criteria>
        <criteria operator="AND" comment="vista/2008/versions/Core services 6.0">
          <extend_definition comment="Microsoft XML Core Services 6 is installed" definition_ref="oval:org.mitre.oval:def:454"/>
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criterion comment="Check if the version of Msxml6.dll is less than 6.20.5007.0" test_ref="oval:org.mitre.oval:tst:114749"/>
        </criteria>
        <criteria operator="AND" comment="win7/2008 r2/versions/Core services 3.0">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of Msxml3.dll is less than 8.110.7601.18431" test_ref="oval:org.mitre.oval:tst:114835"/>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of Msxml3.dll is less than 8.110.7601.22640" test_ref="oval:org.mitre.oval:tst:114525"/>
              <criterion comment="Check if version of Msxml3.dll is greater than or equal to 8.110.7601.22000" test_ref="oval:org.mitre.oval:tst:79072"/>
            </criteria>
          </criteria>
          <extend_definition comment="Microsoft XML Core Services 3 is installed" definition_ref="oval:org.mitre.oval:def:415"/>
        </criteria>
        <criteria operator="AND" comment="win7/2008 r2/versions/Core services 6.0">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of Msxml6.dll is less than 6.30.7601.18431" test_ref="oval:org.mitre.oval:tst:114941"/>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of Msxml6.dll is less than 6.30.7601.22640" test_ref="oval:org.mitre.oval:tst:114376"/>
              <criterion comment="Check if version of Msxml6.dll is greater than or equal to 6.30.7601.22000" test_ref="oval:org.mitre.oval:tst:79900"/>
            </criteria>
          </criteria>
          <extend_definition comment="Microsoft XML Core Services 6 is installed" definition_ref="oval:org.mitre.oval:def:454"/>
        </criteria>
        <criteria operator="AND" comment="win8/2012/versions">
          <extend_definition comment="Microsoft XML Core Services 3 is installed" definition_ref="oval:org.mitre.oval:def:415"/>
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of Msxml3.dll is less than 8.110.9200.16863" test_ref="oval:org.mitre.oval:tst:114488"/>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of Msxml3.dll is less than 8.110.9200.20982" test_ref="oval:org.mitre.oval:tst:114321"/>
              <criterion comment="Check if the version of msxml3.dll is greater than or equal to 8.110.9200.20000" test_ref="oval:org.mitre.oval:tst:80548"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="win 8.1/2012 r2/versions">
          <extend_definition comment="Microsoft XML Core Services 3 is installed" definition_ref="oval:org.mitre.oval:def:415"/>
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of Msxml3.dll is less than 8.110.9600.16663" test_ref="oval:org.mitre.oval:tst:114638"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:454" version="3" class="inventory">
      <metadata>
        <title>Microsoft XML Core Services 6 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft XML Core Services 6</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:xml_core_services:6"/>
        <description>Microsoft XML Core Services 6 is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-10-11T05:29:41">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-10-13T14:55:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-31T19:35:42.283-05:00">INTERIM</status_change>
            <status_change date="2006-11-21T21:27:51.747-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:454 - products added to inventories" date="2015-04-17T09:39:00.289-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-04-17T09:41:23.422-04:00">INTERIM</status_change>
            <status_change date="2015-05-04T04:00:19.661-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="Microsoft XML Core Services 6 is installed." test_ref="oval:org.mitre.oval:tst:182"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24946" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability (CVE-2014-1789) - MS14-035</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <product>Microsoft Internet Explorer 10</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-1789" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1789"/>
        <description>Microsoft Internet Explorer 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-1790.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-06-16T09:23:20">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-06-20T11:21:25.837-04:00">DRAFT</status_change>
            <status_change date="2014-07-07T04:01:30.524-04:00">INTERIM</status_change>
            <status_change date="2014-07-28T04:00:41.578-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24946 - Updated to remove SP checks." date="2014-08-07T14:51:00.976-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-08-07T14:55:06.352-04:00">INTERIM</status_change>
            <status_change date="2014-08-25T04:00:46.496-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
        <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
          <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
          <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
          <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
          <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
          <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
        </criteria>
        <criteria operator="OR" comment="Check for vulnerable versions">
          <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16921" test_ref="oval:org.mitre.oval:tst:114739"/>
          <criteria operator="AND" comment="Check for LDR">
            <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21044" test_ref="oval:org.mitre.oval:tst:114922"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24945" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability (CVE-2014-1800) - MS14-035</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-1800" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1800"/>
        <description>Microsoft Internet Explorer 8 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-06-16T09:23:20">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-06-20T11:21:20.912-04:00">DRAFT</status_change>
            <status_change date="2014-07-07T04:01:29.558-04:00">INTERIM</status_change>
            <status_change date="2014-07-28T04:00:41.258-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24945 - Updated to remove SP checks." date="2014-08-07T14:55:00.409-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-08-07T14:56:49.902-04:00">INTERIM</status_change>
            <status_change date="2014-08-25T04:00:45.863-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23598" test_ref="oval:org.mitre.oval:tst:114669"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19539" test_ref="oval:org.mitre.oval:tst:114916"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23598" test_ref="oval:org.mitre.oval:tst:114669"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18472" test_ref="oval:org.mitre.oval:tst:114770"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22686" test_ref="oval:org.mitre.oval:tst:114915"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16555" test_ref="oval:org.mitre.oval:tst:114960"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20666" test_ref="oval:org.mitre.oval:tst:114734"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16921" test_ref="oval:org.mitre.oval:tst:114739"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21044" test_ref="oval:org.mitre.oval:tst:114922"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16668" test_ref="oval:org.mitre.oval:tst:114145"/>
                <criteria operator="AND" comment="kb2957689 and kb2929437">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 11.0.9600.17041" test_ref="oval:org.mitre.oval:tst:113778"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17126" test_ref="oval:org.mitre.oval:tst:113991"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 8.1 / 2k12 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16668" test_ref="oval:org.mitre.oval:tst:114145"/>
                <criteria operator="AND" comment="kb2957689 and kb2919355">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 11.0.9600.17037" test_ref="oval:org.mitre.oval:tst:114108"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17126" test_ref="oval:org.mitre.oval:tst:113991"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24933" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability (CVE-2014-2759) - MS14-035</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-2759" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2759"/>
        <description>Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-1773, CVE-2014-1783, CVE-2014-1784, CVE-2014-1786, CVE-2014-1795, CVE-2014-1805, CVE-2014-2758, CVE-2014-2765, CVE-2014-2766, and CVE-2014-2775.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-06-16T09:23:20">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-06-20T11:22:38.413-04:00">DRAFT</status_change>
            <status_change date="2014-07-07T04:01:28.440-04:00">INTERIM</status_change>
            <status_change date="2014-07-28T04:00:39.991-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24933 - Updated to remove SP checks." date="2014-08-07T14:55:00.409-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-08-07T14:56:53.011-04:00">INTERIM</status_change>
            <status_change date="2014-08-25T04:00:44.314-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16555" test_ref="oval:org.mitre.oval:tst:114960"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20666" test_ref="oval:org.mitre.oval:tst:114734"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16921" test_ref="oval:org.mitre.oval:tst:114739"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21044" test_ref="oval:org.mitre.oval:tst:114922"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16668" test_ref="oval:org.mitre.oval:tst:114145"/>
                <criteria operator="AND" comment="kb2957689 and kb2929437">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 11.0.9600.17041" test_ref="oval:org.mitre.oval:tst:113778"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17126" test_ref="oval:org.mitre.oval:tst:113991"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 8.1 / 2k12 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16668" test_ref="oval:org.mitre.oval:tst:114145"/>
                <criteria operator="AND" comment="kb2957689 and kb2919355">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 11.0.9600.17037" test_ref="oval:org.mitre.oval:tst:114108"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17126" test_ref="oval:org.mitre.oval:tst:113991"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24928" version="5" class="vulnerability">
      <metadata>
        <title>Memory corruption vulnerability in Internet Explorer (CVE-2014-1779) - MS14-035</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-1796" ref_url="http://www.scaprepo.com/view.jsp?id=CVE-2014-1796"/>
        <description>Microsoft Internet Explorer 6 and 8 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-06-16T09:54:22">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-06-20T11:22:24.630-04:00">DRAFT</status_change>
            <status_change date="2014-07-07T04:01:28.058-04:00">INTERIM</status_change>
            <status_change date="2014-07-28T04:00:39.412-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24928 - Updated to remove SP checks." date="2014-08-07T14:51:00.976-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-08-07T14:55:09.117-04:00">INTERIM</status_change>
            <status_change date="2014-08-25T04:00:43.792-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5341" test_ref="oval:org.mitre.oval:tst:114964"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21389" test_ref="oval:org.mitre.oval:tst:114956"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista/2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19098" test_ref="oval:org.mitre.oval:tst:114438"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23389" test_ref="oval:org.mitre.oval:tst:114853"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23598" test_ref="oval:org.mitre.oval:tst:114669"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19539" test_ref="oval:org.mitre.oval:tst:114916"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23598" test_ref="oval:org.mitre.oval:tst:114669"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18472" test_ref="oval:org.mitre.oval:tst:114770"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22686" test_ref="oval:org.mitre.oval:tst:114915"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16555" test_ref="oval:org.mitre.oval:tst:114960"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20666" test_ref="oval:org.mitre.oval:tst:114734"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16921" test_ref="oval:org.mitre.oval:tst:114739"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21044" test_ref="oval:org.mitre.oval:tst:114922"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16668" test_ref="oval:org.mitre.oval:tst:114145"/>
                <criteria operator="AND" comment="kb2957689 and kb2929437">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 11.0.9600.17041" test_ref="oval:org.mitre.oval:tst:113778"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17126" test_ref="oval:org.mitre.oval:tst:113991"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 8.1 / 2k12 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16668" test_ref="oval:org.mitre.oval:tst:114145"/>
                <criteria operator="AND" comment="kb2957689 and kb2919355">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 11.0.9600.17037" test_ref="oval:org.mitre.oval:tst:114108"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17126" test_ref="oval:org.mitre.oval:tst:113991"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24925" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability (CVE-2014-1780) - MS14-035</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-1780" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1780"/>
        <description>Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-1772, CVE-2014-1794, CVE-2014-1797, CVE-2014-1802, CVE-2014-2756, CVE-2014-2763, CVE-2014-2764, CVE-2014-2769, and CVE-2014-2771.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-06-16T09:23:20">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-06-20T11:22:06.419-04:00">DRAFT</status_change>
            <status_change date="2014-07-07T04:01:27.899-04:00">INTERIM</status_change>
            <status_change date="2014-07-28T04:00:39.142-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24925 - Updated to remove SP checks." date="2014-08-07T14:55:00.409-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-08-07T14:56:53.729-04:00">INTERIM</status_change>
            <status_change date="2014-08-25T04:00:43.459-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16921" test_ref="oval:org.mitre.oval:tst:114739"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21044" test_ref="oval:org.mitre.oval:tst:114922"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16668" test_ref="oval:org.mitre.oval:tst:114145"/>
                <criteria operator="AND" comment="kb2957689 and kb2929437">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 11.0.9600.17041" test_ref="oval:org.mitre.oval:tst:113778"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17126" test_ref="oval:org.mitre.oval:tst:113991"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 8.1 / 2k12 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16668" test_ref="oval:org.mitre.oval:tst:114145"/>
                <criteria operator="AND" comment="kb2957689 and kb2919355">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 11.0.9600.17037" test_ref="oval:org.mitre.oval:tst:114108"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17126" test_ref="oval:org.mitre.oval:tst:113991"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24921" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability (CVE-2014-2757) - MS14-035</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-2757" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2757"/>
        <description>Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-0282, CVE-2014-1775, CVE-2014-1779, CVE-2014-1799, and CVE-2014-1803.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-06-16T09:23:20">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-06-20T11:22:53.859-04:00">DRAFT</status_change>
            <status_change date="2014-07-07T04:01:27.575-04:00">INTERIM</status_change>
            <status_change date="2014-07-28T04:00:38.291-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24921 - Updated to remove SP checks." date="2014-08-07T14:51:00.976-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-08-07T14:55:05.622-04:00">INTERIM</status_change>
            <status_change date="2014-08-25T04:00:42.915-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5341" test_ref="oval:org.mitre.oval:tst:114964"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21389" test_ref="oval:org.mitre.oval:tst:114956"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista/2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19098" test_ref="oval:org.mitre.oval:tst:114438"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23389" test_ref="oval:org.mitre.oval:tst:114853"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23598" test_ref="oval:org.mitre.oval:tst:114669"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19539" test_ref="oval:org.mitre.oval:tst:114916"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23598" test_ref="oval:org.mitre.oval:tst:114669"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18472" test_ref="oval:org.mitre.oval:tst:114770"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22686" test_ref="oval:org.mitre.oval:tst:114915"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16555" test_ref="oval:org.mitre.oval:tst:114960"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20666" test_ref="oval:org.mitre.oval:tst:114734"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16921" test_ref="oval:org.mitre.oval:tst:114739"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21044" test_ref="oval:org.mitre.oval:tst:114922"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16668" test_ref="oval:org.mitre.oval:tst:114145"/>
                <criteria operator="AND" comment="kb2957689 and kb2929437">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 11.0.9600.17041" test_ref="oval:org.mitre.oval:tst:113778"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17126" test_ref="oval:org.mitre.oval:tst:113991"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 8.1 / 2k12 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16668" test_ref="oval:org.mitre.oval:tst:114145"/>
                <criteria operator="AND" comment="kb2957689 and kb2919355">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 11.0.9600.17037" test_ref="oval:org.mitre.oval:tst:114108"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17126" test_ref="oval:org.mitre.oval:tst:113991"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24913" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability (CVE-2014-1773) - MS14-035</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-1773" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1773"/>
        <description>Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-1783, CVE-2014-1784, CVE-2014-1786, CVE-2014-1795, CVE-2014-1805, CVE-2014-2758, CVE-2014-2759, CVE-2014-2765, CVE-2014-2766, and CVE-2014-2775.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-06-16T09:23:20">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-06-20T11:21:54.299-04:00">DRAFT</status_change>
            <status_change date="2014-07-07T04:01:27.277-04:00">INTERIM</status_change>
            <status_change date="2014-07-28T04:00:37.546-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24913 - Updated to remove SP checks." date="2014-08-07T14:55:00.409-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-08-07T14:56:54.070-04:00">INTERIM</status_change>
            <status_change date="2014-08-25T04:00:41.932-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16555" test_ref="oval:org.mitre.oval:tst:114960"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20666" test_ref="oval:org.mitre.oval:tst:114734"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16921" test_ref="oval:org.mitre.oval:tst:114739"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21044" test_ref="oval:org.mitre.oval:tst:114922"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16668" test_ref="oval:org.mitre.oval:tst:114145"/>
                <criteria operator="AND" comment="kb2957689 and kb2929437">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 11.0.9600.17041" test_ref="oval:org.mitre.oval:tst:113778"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17126" test_ref="oval:org.mitre.oval:tst:113991"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 8.1 / 2k12 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16668" test_ref="oval:org.mitre.oval:tst:114145"/>
                <criteria operator="AND" comment="kb2957689 and kb2919355">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 11.0.9600.17037" test_ref="oval:org.mitre.oval:tst:114108"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17126" test_ref="oval:org.mitre.oval:tst:113991"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24912" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability (CVE-2014-0282) - MS14-035</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-0282" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0282"/>
        <description>Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-1775, CVE-2014-1779, CVE-2014-1799, CVE-2014-1803, and CVE-2014-2757.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-06-16T09:23:20">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-06-20T11:22:36.396-04:00">DRAFT</status_change>
            <status_change date="2014-07-07T04:01:26.867-04:00">INTERIM</status_change>
            <status_change date="2014-07-28T04:00:37.066-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24912 - Updated to remove SP checks." date="2014-08-07T14:51:00.976-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-08-07T14:55:12.777-04:00">INTERIM</status_change>
            <status_change date="2014-08-25T04:00:41.418-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5341" test_ref="oval:org.mitre.oval:tst:114964"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21389" test_ref="oval:org.mitre.oval:tst:114956"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista/2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19098" test_ref="oval:org.mitre.oval:tst:114438"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23389" test_ref="oval:org.mitre.oval:tst:114853"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23598" test_ref="oval:org.mitre.oval:tst:114669"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19539" test_ref="oval:org.mitre.oval:tst:114916"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23598" test_ref="oval:org.mitre.oval:tst:114669"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18472" test_ref="oval:org.mitre.oval:tst:114770"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22686" test_ref="oval:org.mitre.oval:tst:114915"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16555" test_ref="oval:org.mitre.oval:tst:114960"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20666" test_ref="oval:org.mitre.oval:tst:114734"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16921" test_ref="oval:org.mitre.oval:tst:114739"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21044" test_ref="oval:org.mitre.oval:tst:114922"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16668" test_ref="oval:org.mitre.oval:tst:114145"/>
                <criteria operator="AND" comment="kb2957689 and kb2929437">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 11.0.9600.17041" test_ref="oval:org.mitre.oval:tst:113778"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17126" test_ref="oval:org.mitre.oval:tst:113991"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 8.1 / 2k12 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16668" test_ref="oval:org.mitre.oval:tst:114145"/>
                <criteria operator="AND" comment="kb2957689 and kb2919355">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 11.0.9600.17037" test_ref="oval:org.mitre.oval:tst:114108"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17126" test_ref="oval:org.mitre.oval:tst:113991"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24910" version="6" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability - CVE-2014-2792 (MS14-037)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-2792" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2792"/>
        <description>Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-2786 and CVE-2014-2813.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-07-11T08:33:30">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-07-11T11:47:37.125-04:00">DRAFT</status_change>
            <status_change date="2014-07-28T04:00:36.789-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24910 - Updated to remove SP checks." date="2014-08-07T14:56:00.647-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-08-25T04:00:40.970-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16561" test_ref="oval:org.mitre.oval:tst:114824"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20672" test_ref="oval:org.mitre.oval:tst:115308"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17028" test_ref="oval:org.mitre.oval:tst:115430"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21145" test_ref="oval:org.mitre.oval:tst:115571"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16672" test_ref="oval:org.mitre.oval:tst:115696"/>
                <criteria operator="AND" comment="kb2957689 and kb2929437">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 11.0.9600.17041" test_ref="oval:org.mitre.oval:tst:113778"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17207" test_ref="oval:org.mitre.oval:tst:115689"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 8.1 / 2k12 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16672" test_ref="oval:org.mitre.oval:tst:115696"/>
                <criteria operator="AND" comment="kb2957689 and kb2919355">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 11.0.9600.17037" test_ref="oval:org.mitre.oval:tst:114108"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17207" test_ref="oval:org.mitre.oval:tst:115689"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24903" version="3" class="vulnerability">
      <metadata>
        <title>Vulnerability in TCP Protocol could allow denial of service - CVE-2014-1811 (MS14-031)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-1811" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1811"/>
        <description>The TCP implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to cause a denial of service (non-paged pool memory consumption and system hang) via malformed data in the Options field of a TCP header, aka "TCP Denial of Service Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-06-16T15:41:45">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-06-20T11:12:24.570-04:00">DRAFT</status_change>
            <status_change date="2014-07-07T04:01:26.561-04:00">INTERIM</status_change>
            <status_change date="2014-07-28T04:00:36.307-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Windows Vista / Server 2008 and vulnerable file version">
          <criteria operator="OR" comment="Win Vista/ Server 2008">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
            <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of tcpip.sys is less than 6.0.6002.19080" test_ref="oval:org.mitre.oval:tst:114852"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of tcpip.sys is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80825"/>
              <criterion comment="Check if the version of tcpip.sys is less than 6.0.6002.23370" test_ref="oval:org.mitre.oval:tst:114891"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Windows 7 / 2008 R2 and vulnerable file versions">
          <criteria operator="OR" comment="Windows 7 / 2008 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12292"/>
            <extend_definition comment="Microsoft Windows 7 x64 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12627"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12567"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12583"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of tcpip.sys is less than 6.1.7601.18438" test_ref="oval:org.mitre.oval:tst:114905"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of tcpip.sys is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:81171"/>
              <criterion comment="Check if the version of tcpip.sys is less than 6.1.7601.22648" test_ref="oval:org.mitre.oval:tst:114908"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8 / 2012 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2012">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of tcpip.sys is less than 6.2.9200.16886" test_ref="oval:org.mitre.oval:tst:114909"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of tcpip.sys is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:114778"/>
              <criterion comment="Check if the version of tcpip.sys is less than 6.2.9200.21005" test_ref="oval:org.mitre.oval:tst:114708"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="8.1/ 2012 R2 and vulnerable file version">
          <criteria operator="OR" comment="8.1/ 2012 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criteria operator="OR" comment="either version">
            <criteria operator="AND" comment="kb2957189 and kb2919355">
              <criterion comment="Check if the version of tcpip.sys is less than 6.3.9600.17088" test_ref="oval:org.mitre.oval:tst:114093"/>
              <criterion comment="Check if the version of tcpip.sys is greater than or equal to 6.3.9600.17039" test_ref="oval:org.mitre.oval:tst:114935"/>
            </criteria>
            <criterion comment="Check if the version of tcpip.sys is less than 6.3.9600.16660" test_ref="oval:org.mitre.oval:tst:114088"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24902" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability (CVE-2014-2756) - MS14-035</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-2756" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2756"/>
        <description>Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-1772, CVE-2014-1780, CVE-2014-1794, CVE-2014-1797, CVE-2014-1802, CVE-2014-2763, CVE-2014-2764, CVE-2014-2769, and CVE-2014-2771.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-06-16T09:23:20">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-06-20T11:22:58.826-04:00">DRAFT</status_change>
            <status_change date="2014-07-07T04:01:26.407-04:00">INTERIM</status_change>
            <status_change date="2014-07-28T04:00:36.084-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24902 - Updated to remove SP checks." date="2014-08-07T14:51:00.976-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-08-07T14:55:06.619-04:00">INTERIM</status_change>
            <status_change date="2014-08-25T04:00:40.247-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16921" test_ref="oval:org.mitre.oval:tst:114739"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21044" test_ref="oval:org.mitre.oval:tst:114922"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16668" test_ref="oval:org.mitre.oval:tst:114145"/>
                <criteria operator="AND" comment="kb2957689 and kb2929437">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 11.0.9600.17041" test_ref="oval:org.mitre.oval:tst:113778"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17126" test_ref="oval:org.mitre.oval:tst:113991"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 8.1 / 2k12 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16668" test_ref="oval:org.mitre.oval:tst:114145"/>
                <criteria operator="AND" comment="kb2957689 and kb2919355">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 11.0.9600.17037" test_ref="oval:org.mitre.oval:tst:114108"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17126" test_ref="oval:org.mitre.oval:tst:113991"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24901" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability (CVE-2014-2766) - MS14-035</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-2766" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2766"/>
        <description>Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-1773, CVE-2014-1783, CVE-2014-1784, CVE-2014-1786, CVE-2014-1795, CVE-2014-1805, CVE-2014-2758, CVE-2014-2759, CVE-2014-2765, and CVE-2014-2775.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-06-16T09:23:20">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-06-20T11:23:05.034-04:00">DRAFT</status_change>
            <status_change date="2014-07-07T04:01:26.164-04:00">INTERIM</status_change>
            <status_change date="2014-07-28T04:00:35.842-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24901 - Updated to remove SP checks." date="2014-08-07T14:51:00.976-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-08-07T14:55:11.923-04:00">INTERIM</status_change>
            <status_change date="2014-08-25T04:00:39.801-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16555" test_ref="oval:org.mitre.oval:tst:114960"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20666" test_ref="oval:org.mitre.oval:tst:114734"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16921" test_ref="oval:org.mitre.oval:tst:114739"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21044" test_ref="oval:org.mitre.oval:tst:114922"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16668" test_ref="oval:org.mitre.oval:tst:114145"/>
                <criteria operator="AND" comment="kb2957689 and kb2929437">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 11.0.9600.17041" test_ref="oval:org.mitre.oval:tst:113778"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17126" test_ref="oval:org.mitre.oval:tst:113991"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 8.1 / 2k12 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16668" test_ref="oval:org.mitre.oval:tst:114145"/>
                <criteria operator="AND" comment="kb2957689 and kb2919355">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 11.0.9600.17037" test_ref="oval:org.mitre.oval:tst:114108"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17126" test_ref="oval:org.mitre.oval:tst:113991"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24899" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability (CVE-2014-1779) - MS14-035</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-1779" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1779"/>
        <description>Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-0282, CVE-2014-1775, CVE-2014-1799, CVE-2014-1803, and CVE-2014-2757.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-06-16T09:23:20">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-06-20T11:23:03.059-04:00">DRAFT</status_change>
            <status_change date="2014-07-07T04:01:25.884-04:00">INTERIM</status_change>
            <status_change date="2014-07-28T04:00:35.532-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24899 - Updated to remove SP checks." date="2014-08-07T14:55:00.409-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-08-07T14:56:49.402-04:00">INTERIM</status_change>
            <status_change date="2014-08-25T04:00:39.241-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5341" test_ref="oval:org.mitre.oval:tst:114964"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21389" test_ref="oval:org.mitre.oval:tst:114956"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista/2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19098" test_ref="oval:org.mitre.oval:tst:114438"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23389" test_ref="oval:org.mitre.oval:tst:114853"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23598" test_ref="oval:org.mitre.oval:tst:114669"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19539" test_ref="oval:org.mitre.oval:tst:114916"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23598" test_ref="oval:org.mitre.oval:tst:114669"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18472" test_ref="oval:org.mitre.oval:tst:114770"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22686" test_ref="oval:org.mitre.oval:tst:114915"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16555" test_ref="oval:org.mitre.oval:tst:114960"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20666" test_ref="oval:org.mitre.oval:tst:114734"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16921" test_ref="oval:org.mitre.oval:tst:114739"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21044" test_ref="oval:org.mitre.oval:tst:114922"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16668" test_ref="oval:org.mitre.oval:tst:114145"/>
                <criteria operator="AND" comment="kb2957689 and kb2929437">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 11.0.9600.17041" test_ref="oval:org.mitre.oval:tst:113778"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17126" test_ref="oval:org.mitre.oval:tst:113991"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 8.1 / 2k12 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16668" test_ref="oval:org.mitre.oval:tst:114145"/>
                <criteria operator="AND" comment="kb2957689 and kb2919355">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 11.0.9600.17037" test_ref="oval:org.mitre.oval:tst:114108"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17126" test_ref="oval:org.mitre.oval:tst:113991"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24898" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability (CVE-2014-2765) - MS14-035</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-2765" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2765"/>
        <description>Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-1773, CVE-2014-1783, CVE-2014-1784, CVE-2014-1786, CVE-2014-1795, CVE-2014-1805, CVE-2014-2758, CVE-2014-2759, CVE-2014-2766, and CVE-2014-2775.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-06-16T09:23:20">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-06-20T11:21:49.518-04:00">DRAFT</status_change>
            <status_change date="2014-07-07T04:01:25.645-04:00">INTERIM</status_change>
            <status_change date="2014-07-28T04:00:35.185-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24898 - Updated to remove SP checks." date="2014-08-07T14:51:00.976-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-08-07T14:55:16.217-04:00">INTERIM</status_change>
            <status_change date="2014-08-25T04:00:38.705-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16555" test_ref="oval:org.mitre.oval:tst:114960"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20666" test_ref="oval:org.mitre.oval:tst:114734"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16921" test_ref="oval:org.mitre.oval:tst:114739"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21044" test_ref="oval:org.mitre.oval:tst:114922"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16668" test_ref="oval:org.mitre.oval:tst:114145"/>
                <criteria operator="AND" comment="kb2957689 and kb2929437">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 11.0.9600.17041" test_ref="oval:org.mitre.oval:tst:113778"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17126" test_ref="oval:org.mitre.oval:tst:113991"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 8.1 / 2k12 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16668" test_ref="oval:org.mitre.oval:tst:114145"/>
                <criteria operator="AND" comment="kb2957689 and kb2919355">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 11.0.9600.17037" test_ref="oval:org.mitre.oval:tst:114108"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17126" test_ref="oval:org.mitre.oval:tst:113991"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24896" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability (CVE-2014-1783) - MS14-035</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-1783" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1783"/>
        <description>Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-1773, CVE-2014-1784, CVE-2014-1786, CVE-2014-1795, CVE-2014-1805, CVE-2014-2758, CVE-2014-2759, CVE-2014-2765, CVE-2014-2766, and CVE-2014-2775.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-06-16T09:23:20">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-06-20T11:22:02.335-04:00">DRAFT</status_change>
            <status_change date="2014-07-07T04:01:25.421-04:00">INTERIM</status_change>
            <status_change date="2014-07-28T04:00:34.787-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24896 - Updated to remove SP checks." date="2014-08-07T14:51:00.976-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-08-07T14:55:12.293-04:00">INTERIM</status_change>
            <status_change date="2014-08-25T04:00:38.307-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16555" test_ref="oval:org.mitre.oval:tst:114960"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20666" test_ref="oval:org.mitre.oval:tst:114734"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16921" test_ref="oval:org.mitre.oval:tst:114739"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21044" test_ref="oval:org.mitre.oval:tst:114922"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16668" test_ref="oval:org.mitre.oval:tst:114145"/>
                <criteria operator="AND" comment="kb2957689 and kb2929437">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 11.0.9600.17041" test_ref="oval:org.mitre.oval:tst:113778"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17126" test_ref="oval:org.mitre.oval:tst:113991"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 8.1 / 2k12 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16668" test_ref="oval:org.mitre.oval:tst:114145"/>
                <criteria operator="AND" comment="kb2957689 and kb2919355">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 11.0.9600.17037" test_ref="oval:org.mitre.oval:tst:114108"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17126" test_ref="oval:org.mitre.oval:tst:113991"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24895" version="6" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability - CVE-2014-2798 (MS14-037)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-2798" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2798"/>
        <description>Microsoft Internet Explorer 8 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-2789, CVE-2014-2795, and CVE-2014-2804.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-07-11T08:33:30">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-07-11T11:47:47.723-04:00">DRAFT</status_change>
            <status_change date="2014-07-28T04:00:34.528-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24895 - Updated to remove SP checks." date="2014-08-07T14:56:00.647-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-08-25T04:00:37.768-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23603" test_ref="oval:org.mitre.oval:tst:115559"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19543" test_ref="oval:org.mitre.oval:tst:114962"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23603" test_ref="oval:org.mitre.oval:tst:115559"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18487" test_ref="oval:org.mitre.oval:tst:115377"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22703" test_ref="oval:org.mitre.oval:tst:115320"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16561" test_ref="oval:org.mitre.oval:tst:114824"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20672" test_ref="oval:org.mitre.oval:tst:115308"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17028" test_ref="oval:org.mitre.oval:tst:115430"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21145" test_ref="oval:org.mitre.oval:tst:115571"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16672" test_ref="oval:org.mitre.oval:tst:115696"/>
                <criteria operator="AND" comment="kb2957689 and kb2929437">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 11.0.9600.17041" test_ref="oval:org.mitre.oval:tst:113778"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17207" test_ref="oval:org.mitre.oval:tst:115689"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 8.1 / 2k12 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16672" test_ref="oval:org.mitre.oval:tst:115696"/>
                <criteria operator="AND" comment="kb2957689 and kb2919355">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 11.0.9600.17037" test_ref="oval:org.mitre.oval:tst:114108"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17207" test_ref="oval:org.mitre.oval:tst:115689"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24890" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability (CVE-2014-1790) - MS14-035</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <product>Microsoft Internet Explorer 10</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-1790" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1790"/>
        <description>Microsoft Internet Explorer 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-1789.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-06-16T09:23:20">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-06-20T11:21:21.951-04:00">DRAFT</status_change>
            <status_change date="2014-07-07T04:01:25.213-04:00">INTERIM</status_change>
            <status_change date="2014-07-28T04:00:34.361-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24890 - Updated to remove SP checks." date="2014-08-07T14:55:00.409-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-08-07T14:56:55.353-04:00">INTERIM</status_change>
            <status_change date="2014-08-25T04:00:37.424-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
        <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
          <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
          <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
          <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
          <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
          <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
        </criteria>
        <criteria operator="OR" comment="Check for vulnerable versions">
          <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16921" test_ref="oval:org.mitre.oval:tst:114739"/>
          <criteria operator="AND" comment="Check for LDR">
            <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21044" test_ref="oval:org.mitre.oval:tst:114922"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24882" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability (CVE-2014-1771) - MS14-035</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-1771" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1771"/>
        <description>SChannel in Microsoft Internet Explorer 6 through 11 does not ensure that a server's X.509 certificate is the same during renegotiation as it was before renegotiation, which allows man-in-the-middle attackers to obtain sensitive information or modify TLS session data via a "triple handshake attack," aka "TLS Server Certificate Renegotiation Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-06-16T09:23:20">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-06-20T11:21:43.805-04:00">DRAFT</status_change>
            <status_change date="2014-07-07T04:01:24.315-04:00">INTERIM</status_change>
            <status_change date="2014-07-28T04:00:33.185-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24882 - Updated to remove SP checks." date="2014-08-07T14:56:00.647-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-08-07T14:58:20.131-04:00">INTERIM</status_change>
            <status_change date="2014-08-25T04:00:36.928-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5341" test_ref="oval:org.mitre.oval:tst:114964"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21389" test_ref="oval:org.mitre.oval:tst:114956"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista/2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19098" test_ref="oval:org.mitre.oval:tst:114438"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23389" test_ref="oval:org.mitre.oval:tst:114853"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23598" test_ref="oval:org.mitre.oval:tst:114669"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19539" test_ref="oval:org.mitre.oval:tst:114916"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23598" test_ref="oval:org.mitre.oval:tst:114669"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18472" test_ref="oval:org.mitre.oval:tst:114770"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22686" test_ref="oval:org.mitre.oval:tst:114915"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16555" test_ref="oval:org.mitre.oval:tst:114960"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20666" test_ref="oval:org.mitre.oval:tst:114734"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16921" test_ref="oval:org.mitre.oval:tst:114739"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21044" test_ref="oval:org.mitre.oval:tst:114922"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16668" test_ref="oval:org.mitre.oval:tst:114145"/>
                <criteria operator="AND" comment="kb2957689 and kb2929437">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 11.0.9600.17041" test_ref="oval:org.mitre.oval:tst:113778"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17126" test_ref="oval:org.mitre.oval:tst:113991"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 8.1 / 2k12 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16668" test_ref="oval:org.mitre.oval:tst:114145"/>
                <criteria operator="AND" comment="kb2957689 and kb2919355">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 11.0.9600.17037" test_ref="oval:org.mitre.oval:tst:114108"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17126" test_ref="oval:org.mitre.oval:tst:113991"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24875" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability (CVE-2014-1802) - MS14-035</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-1802" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1802"/>
        <description>Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-1772, CVE-2014-1780, CVE-2014-1794, CVE-2014-1797, CVE-2014-2756, CVE-2014-2763, CVE-2014-2764, CVE-2014-2769, and CVE-2014-2771.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-06-16T09:23:20">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-06-20T11:22:46.825-04:00">DRAFT</status_change>
            <status_change date="2014-07-07T04:01:24.007-04:00">INTERIM</status_change>
            <status_change date="2014-07-28T04:00:32.836-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24875 - Updated to remove SP checks." date="2014-08-07T14:55:00.409-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-08-07T14:56:53.574-04:00">INTERIM</status_change>
            <status_change date="2014-08-25T04:00:36.559-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16921" test_ref="oval:org.mitre.oval:tst:114739"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21044" test_ref="oval:org.mitre.oval:tst:114922"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16668" test_ref="oval:org.mitre.oval:tst:114145"/>
                <criteria operator="AND" comment="kb2957689 and kb2929437">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 11.0.9600.17041" test_ref="oval:org.mitre.oval:tst:113778"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17126" test_ref="oval:org.mitre.oval:tst:113991"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 8.1 / 2k12 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16668" test_ref="oval:org.mitre.oval:tst:114145"/>
                <criteria operator="AND" comment="kb2957689 and kb2919355">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 11.0.9600.17037" test_ref="oval:org.mitre.oval:tst:114108"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17126" test_ref="oval:org.mitre.oval:tst:113991"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24825" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability (CVE-2014-2764) - MS14-035</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-2764" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2764"/>
        <description>Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-1772, CVE-2014-1780, CVE-2014-1794, CVE-2014-1797, CVE-2014-1802, CVE-2014-2756, CVE-2014-2763, CVE-2014-2769, and CVE-2014-2771.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-06-16T09:23:20">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-06-20T11:22:21.673-04:00">DRAFT</status_change>
            <status_change date="2014-07-07T04:01:21.897-04:00">INTERIM</status_change>
            <status_change date="2014-07-28T04:00:31.468-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24825 - Updated to remove SP checks." date="2014-08-07T14:55:00.409-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-08-07T14:56:49.154-04:00">INTERIM</status_change>
            <status_change date="2014-08-25T04:00:35.753-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16921" test_ref="oval:org.mitre.oval:tst:114739"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21044" test_ref="oval:org.mitre.oval:tst:114922"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16668" test_ref="oval:org.mitre.oval:tst:114145"/>
                <criteria operator="AND" comment="kb2957689 and kb2929437">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 11.0.9600.17041" test_ref="oval:org.mitre.oval:tst:113778"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17126" test_ref="oval:org.mitre.oval:tst:113991"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 8.1 / 2k12 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16668" test_ref="oval:org.mitre.oval:tst:114145"/>
                <criteria operator="AND" comment="kb2957689 and kb2919355">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 11.0.9600.17037" test_ref="oval:org.mitre.oval:tst:114108"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17126" test_ref="oval:org.mitre.oval:tst:113991"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24823" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability (CVE-2014-1762) - MS14-035</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-1762" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1762"/>
        <description>Unspecified vulnerability in Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code with medium-integrity privileges and bypass a sandbox protection mechanism via unknown vectors, as demonstrated by ZDI during a Pwn4Fun competition at CanSecWest 2014.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-06-16T09:23:20">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-06-20T11:22:50.922-04:00">DRAFT</status_change>
            <status_change date="2014-07-07T04:01:21.600-04:00">INTERIM</status_change>
            <status_change date="2014-07-28T04:00:30.999-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24823 - Updated to remove SP checks." date="2014-08-07T14:56:00.647-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-08-07T14:58:17.887-04:00">INTERIM</status_change>
            <status_change date="2014-08-25T04:00:35.302-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5341" test_ref="oval:org.mitre.oval:tst:114964"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21389" test_ref="oval:org.mitre.oval:tst:114956"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista/2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19098" test_ref="oval:org.mitre.oval:tst:114438"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23389" test_ref="oval:org.mitre.oval:tst:114853"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23598" test_ref="oval:org.mitre.oval:tst:114669"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19539" test_ref="oval:org.mitre.oval:tst:114916"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23598" test_ref="oval:org.mitre.oval:tst:114669"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18472" test_ref="oval:org.mitre.oval:tst:114770"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22686" test_ref="oval:org.mitre.oval:tst:114915"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16555" test_ref="oval:org.mitre.oval:tst:114960"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20666" test_ref="oval:org.mitre.oval:tst:114734"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16921" test_ref="oval:org.mitre.oval:tst:114739"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21044" test_ref="oval:org.mitre.oval:tst:114922"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16668" test_ref="oval:org.mitre.oval:tst:114145"/>
                <criteria operator="AND" comment="kb2957689 and kb2929437">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 11.0.9600.17041" test_ref="oval:org.mitre.oval:tst:113778"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17126" test_ref="oval:org.mitre.oval:tst:113991"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 8.1 / 2k12 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16668" test_ref="oval:org.mitre.oval:tst:114145"/>
                <criteria operator="AND" comment="kb2957689 and kb2919355">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 11.0.9600.17037" test_ref="oval:org.mitre.oval:tst:114108"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17126" test_ref="oval:org.mitre.oval:tst:113991"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24815" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability (CVE-2014-1784) - MS14-035</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-1784" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1784"/>
        <description>Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-1773, CVE-2014-1783, CVE-2014-1786, CVE-2014-1795, CVE-2014-1805, CVE-2014-2758, CVE-2014-2759, CVE-2014-2765, CVE-2014-2766, and CVE-2014-2775.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-06-16T09:23:20">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-06-20T11:21:45.812-04:00">DRAFT</status_change>
            <status_change date="2014-07-07T04:01:21.375-04:00">INTERIM</status_change>
            <status_change date="2014-07-28T04:00:30.605-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24815 - Updated to remove SP checks." date="2014-08-07T14:55:00.409-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-08-07T14:56:49.652-04:00">INTERIM</status_change>
            <status_change date="2014-08-25T04:00:34.822-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16555" test_ref="oval:org.mitre.oval:tst:114960"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20666" test_ref="oval:org.mitre.oval:tst:114734"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16921" test_ref="oval:org.mitre.oval:tst:114739"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21044" test_ref="oval:org.mitre.oval:tst:114922"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16668" test_ref="oval:org.mitre.oval:tst:114145"/>
                <criteria operator="AND" comment="kb2957689 and kb2929437">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 11.0.9600.17041" test_ref="oval:org.mitre.oval:tst:113778"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17126" test_ref="oval:org.mitre.oval:tst:113991"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 8.1 / 2k12 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16668" test_ref="oval:org.mitre.oval:tst:114145"/>
                <criteria operator="AND" comment="kb2957689 and kb2919355">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 11.0.9600.17037" test_ref="oval:org.mitre.oval:tst:114108"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17126" test_ref="oval:org.mitre.oval:tst:113991"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24810" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability (CVE-2014-1775) - MS14-035</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-1775" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1775"/>
        <description>Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-0282, CVE-2014-1779, CVE-2014-1799, CVE-2014-1803, and CVE-2014-2757.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-06-16T09:23:20">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-06-20T11:22:33.451-04:00">DRAFT</status_change>
            <status_change date="2014-07-07T04:01:21.002-04:00">INTERIM</status_change>
            <status_change date="2014-07-28T04:00:30.090-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24810 - Updated to remove SP checks." date="2014-08-07T14:55:00.409-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-08-07T14:56:51.518-04:00">INTERIM</status_change>
            <status_change date="2014-08-25T04:00:34.283-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5341" test_ref="oval:org.mitre.oval:tst:114964"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21389" test_ref="oval:org.mitre.oval:tst:114956"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista/2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19098" test_ref="oval:org.mitre.oval:tst:114438"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23389" test_ref="oval:org.mitre.oval:tst:114853"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23598" test_ref="oval:org.mitre.oval:tst:114669"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19539" test_ref="oval:org.mitre.oval:tst:114916"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23598" test_ref="oval:org.mitre.oval:tst:114669"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18472" test_ref="oval:org.mitre.oval:tst:114770"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22686" test_ref="oval:org.mitre.oval:tst:114915"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16555" test_ref="oval:org.mitre.oval:tst:114960"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20666" test_ref="oval:org.mitre.oval:tst:114734"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16921" test_ref="oval:org.mitre.oval:tst:114739"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21044" test_ref="oval:org.mitre.oval:tst:114922"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16668" test_ref="oval:org.mitre.oval:tst:114145"/>
                <criteria operator="AND" comment="kb2957689 and kb2929437">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 11.0.9600.17041" test_ref="oval:org.mitre.oval:tst:113778"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17126" test_ref="oval:org.mitre.oval:tst:113991"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 8.1 / 2k12 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16668" test_ref="oval:org.mitre.oval:tst:114145"/>
                <criteria operator="AND" comment="kb2957689 and kb2919355">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 11.0.9600.17037" test_ref="oval:org.mitre.oval:tst:114108"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17126" test_ref="oval:org.mitre.oval:tst:113991"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24801" version="3" class="vulnerability">
      <metadata>
        <title>RDP MAC Vulnerability (CVE-2014-0296) - MS14-030</title>
        <affected family="windows">
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-0296" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0296"/>
        <description>The Remote Desktop Protocol (RDP) implementation in Microsoft Windows 7 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 does not properly encrypt sessions, which makes it easier for man-in-the-middle attackers to obtain sensitive information by sniffing the network or modify session content by sending crafted RDP packets, aka "RDP MAC Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-06-16T10:54:24">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-06-20T11:13:43.841-04:00">DRAFT</status_change>
            <status_change date="2014-07-07T04:01:20.686-04:00">INTERIM</status_change>
            <status_change date="2014-07-28T04:00:29.381-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Win 7 and file version">
          <criteria operator="OR" comment="either OS">
            <extend_definition comment="Microsoft Windows 7 (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12292"/>
            <extend_definition comment="Microsoft Windows 7 x64 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12627"/>
          </criteria>
          <criteria operator="OR" comment="LDR / GDR">
            <criterion comment="Check if the version of rdpcorets.dll is less than 6.1.7601.18465" test_ref="oval:org.mitre.oval:tst:114493"/>
            <criteria operator="AND" comment="LDR range">
              <criterion comment="Check if the version of rdpcorets.dll is less than 6.1.7601.22678" test_ref="oval:org.mitre.oval:tst:114473"/>
              <criterion comment="Check if the version of rdpcorets.dll is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:114959"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8 / 2012 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 /2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of rdpcorets.dll is less than 6.2.9200.16912" test_ref="oval:org.mitre.oval:tst:114086"/>
            <criteria operator="AND" comment="Check for LDR range">
              <criterion comment="Check if the version of rdpcorets.dll is greater than or equal to 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:114938"/>
              <criterion comment="Check if the version of rdpcorets.dll is less than 6.2.9200.21035" test_ref="oval:org.mitre.oval:tst:114939"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="8.1/ 2012 R2 and vulnerable file version">
          <criteria operator="OR" comment="8.1/ 2012 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of rdpcorets.dll is less than 6.3.9600.16663" test_ref="oval:org.mitre.oval:tst:113999"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24787" version="3" class="vulnerability">
      <metadata>
        <title>Web Applications Page Content Vulnerability (CVE-2014-1813) - MS14-022</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <product>Microsoft Office Web Apps 2010</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-1813" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1813"/>
        <description>Microsoft Web Applications 2010 SP1 and SP2 allows remote authenticated users to execute arbitrary code via crafted page content, aka "Web Applications Page Content Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-05-26T14:12:20">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-05-27T13:27:06.381-04:00">DRAFT</status_change>
            <status_change date="2014-06-16T04:00:16.303-04:00">INTERIM</status_change>
            <status_change date="2014-07-07T04:01:20.149-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="office web apps sp1/sp2">
          <extend_definition comment="Microsoft Office Web Apps 2010 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:15860"/>
          <extend_definition comment="Microsoft Office Web Apps 2010 Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:19186"/>
        </criteria>
        <criterion comment="Check if the version of SWORD.DLL is less than 14.0.7123.5000" test_ref="oval:org.mitre.oval:tst:114167"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24776" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability (CVE-2014-1785) - MS14-035</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-1786" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1786"/>
        <description>Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-1773, CVE-2014-1783, CVE-2014-1784, CVE-2014-1795, CVE-2014-1805, CVE-2014-2758, CVE-2014-2759, CVE-2014-2765, CVE-2014-2766, and CVE-2014-2775.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-06-16T09:23:20">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-06-20T11:21:30.455-04:00">DRAFT</status_change>
            <status_change date="2014-07-07T04:01:19.840-04:00">INTERIM</status_change>
            <status_change date="2014-07-28T04:00:27.930-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24776 - Updated to remove SP checks." date="2014-08-07T14:56:00.647-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-08-07T14:58:18.415-04:00">INTERIM</status_change>
            <status_change date="2014-08-25T04:00:33.625-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16555" test_ref="oval:org.mitre.oval:tst:114960"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20666" test_ref="oval:org.mitre.oval:tst:114734"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16921" test_ref="oval:org.mitre.oval:tst:114739"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21044" test_ref="oval:org.mitre.oval:tst:114922"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16668" test_ref="oval:org.mitre.oval:tst:114145"/>
                <criteria operator="AND" comment="kb2957689 and kb2929437">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 11.0.9600.17041" test_ref="oval:org.mitre.oval:tst:113778"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17126" test_ref="oval:org.mitre.oval:tst:113991"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 8.1 / 2k12 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16668" test_ref="oval:org.mitre.oval:tst:114145"/>
                <criteria operator="AND" comment="kb2957689 and kb2919355">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 11.0.9600.17037" test_ref="oval:org.mitre.oval:tst:114108"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17126" test_ref="oval:org.mitre.oval:tst:113991"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24744" version="6" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability - CVE-2014-2789 (MS14-037)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-2789" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2789"/>
        <description>Microsoft Internet Explorer 8 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-2795, CVE-2014-2798, and CVE-2014-2804.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-07-11T08:33:30">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-07-11T11:47:31.066-04:00">DRAFT</status_change>
            <status_change date="2014-07-28T04:00:27.187-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24744 - Updated to remove SP checks." date="2014-08-07T14:56:00.647-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-08-25T04:00:32.766-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23603" test_ref="oval:org.mitre.oval:tst:115559"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19543" test_ref="oval:org.mitre.oval:tst:114962"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23603" test_ref="oval:org.mitre.oval:tst:115559"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18487" test_ref="oval:org.mitre.oval:tst:115377"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22703" test_ref="oval:org.mitre.oval:tst:115320"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16561" test_ref="oval:org.mitre.oval:tst:114824"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20672" test_ref="oval:org.mitre.oval:tst:115308"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17028" test_ref="oval:org.mitre.oval:tst:115430"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21145" test_ref="oval:org.mitre.oval:tst:115571"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16672" test_ref="oval:org.mitre.oval:tst:115696"/>
                <criteria operator="AND" comment="kb2957689 and kb2929437">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 11.0.9600.17041" test_ref="oval:org.mitre.oval:tst:113778"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17207" test_ref="oval:org.mitre.oval:tst:115689"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 8.1 / 2k12 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16672" test_ref="oval:org.mitre.oval:tst:115696"/>
                <criteria operator="AND" comment="kb2957689 and kb2919355">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 11.0.9600.17037" test_ref="oval:org.mitre.oval:tst:114108"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17207" test_ref="oval:org.mitre.oval:tst:115689"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24704" version="6" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory corruption vulnerability (CVE-2014-1776) - MS14-021</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-1776" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1776"/>
        <description>Use-after-free vulnerability in Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via vectors related to the CMarkup::IsConnectedToPrimaryMarkup function, as exploited in the wild in April 2014.  NOTE: this issue originally emphasized VGX.DLL, but Microsoft clarified that "VGX.DLL does not contain the vulnerable code leveraged in this exploit. Disabling VGX.DLL is an exploit-specific workaround that provides an immediate, effective workaround to help block known attacks."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-05-07T12:48:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-05-07T13:42:59.565-04:00">DRAFT</status_change>
            <status_change date="2014-05-26T04:06:29.300-04:00">INTERIM</status_change>
            <status_change date="2014-06-16T04:00:14.657-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24704 - extended definitions of OS are without SP checks" date="2014-07-28T18:08:00.084-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T18:10:11.571-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:02:43.990-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="ie6">
          <criteria operator="OR" comment="xp/2003">
            <criteria operator="AND" comment="ie6/xp/version">
              <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
              <criterion comment="Check if the version of mshtml.dll is less than 6.0.2900.6550" test_ref="oval:org.mitre.oval:tst:113946"/>
            </criteria>
            <criteria operator="AND" comment="ie6/xp/2003/versions">
              <criteria operator="OR" comment="xp/2003">
                <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
                <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5328" test_ref="oval:org.mitre.oval:tst:113858"/>
            </criteria>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
        </criteria>
        <criteria operator="AND" comment="ie7">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="xp/2003/vista/2008/">
            <criteria operator="AND" comment="xp/2003/version">
              <criteria operator="OR" comment="either os">
                <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
                <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
                <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21383" test_ref="oval:org.mitre.oval:tst:113947"/>
            </criteria>
            <criteria operator="AND" comment="vista/2008/version">
              <criteria operator="OR" comment="either os">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="gdr/ldr">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19087" test_ref="oval:org.mitre.oval:tst:114090"/>
                <criteria operator="AND" comment="ldr range">
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23377" test_ref="oval:org.mitre.oval:tst:113855"/>
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="ie8">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vista/2008/win7/2008r2//versions">
            <criteria operator="AND" comment="vista/2008/versions">
              <criteria operator="OR" comment="either os">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="gdr/ldr">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19529" test_ref="oval:org.mitre.oval:tst:113843"/>
                <criteria operator="AND" comment="ldr range">
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23588" test_ref="oval:org.mitre.oval:tst:114020"/>
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="win7/2008 r2/version">
              <criteria operator="OR" comment="either os">
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="gdr/ldr">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18446" test_ref="oval:org.mitre.oval:tst:113410"/>
                <criteria operator="AND" comment="ldr range">
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22657" test_ref="oval:org.mitre.oval:tst:113850"/>
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="xp/2003/version">
              <criteria operator="OR" comment="either os">
                <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
                <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23588" test_ref="oval:org.mitre.oval:tst:114020"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="ie9">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16546" test_ref="oval:org.mitre.oval:tst:113116"/>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20657" test_ref="oval:org.mitre.oval:tst:113966"/>
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
            </criteria>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
        </criteria>
        <criteria operator="AND" comment="ie10">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16897" test_ref="oval:org.mitre.oval:tst:114060"/>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21024" test_ref="oval:org.mitre.oval:tst:113720"/>
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.20000" test_ref="oval:org.mitre.oval:tst:80523"/>
            </criteria>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
        </criteria>
        <criteria operator="AND" comment="IE11">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="either OS">
            <criteria operator="AND" comment="7/2008R2/versions">
              <criteria operator="OR" comment="7/2008R2">
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="either version">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16661" test_ref="oval:org.mitre.oval:tst:113948"/>
                <criteria operator="AND" comment="kb2964358 and kb2929437">
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17105" test_ref="oval:org.mitre.oval:tst:114028"/>
                  <criterion comment="Check for mshtml.dll version greater than or equal to 11.0.9600.17041" test_ref="oval:org.mitre.oval:tst:113778"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="8.1/2012R2/versions">
              <criteria operator="OR" comment="8.1/2012R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criteria operator="OR" comment="either version">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16661" test_ref="oval:org.mitre.oval:tst:113948"/>
                <criteria operator="AND" comment="kb2964358 and kb2919355">
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17105" test_ref="oval:org.mitre.oval:tst:114028"/>
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 11.0.9600.17037" test_ref="oval:org.mitre.oval:tst:114108"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24690" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability (CVE-2014-2777) - MS14-035</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-2777" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2777"/>
        <description>Microsoft Internet Explorer 8 through 11 allows remote attackers to execute arbitrary web script with increased privileges via unspecified vectors, aka "Internet Explorer Elevation of Privilege Vulnerability," a different vulnerability than CVE-2014-1778.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-06-16T09:23:20">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-06-20T11:22:10.064-04:00">DRAFT</status_change>
            <status_change date="2014-07-07T04:01:18.531-04:00">INTERIM</status_change>
            <status_change date="2014-07-28T04:00:26.678-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24690 - Updated to remove SP checks." date="2014-08-07T14:55:00.409-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-08-07T14:56:51.132-04:00">INTERIM</status_change>
            <status_change date="2014-08-25T04:00:32.232-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23598" test_ref="oval:org.mitre.oval:tst:114669"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19539" test_ref="oval:org.mitre.oval:tst:114916"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23598" test_ref="oval:org.mitre.oval:tst:114669"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18472" test_ref="oval:org.mitre.oval:tst:114770"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22686" test_ref="oval:org.mitre.oval:tst:114915"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16555" test_ref="oval:org.mitre.oval:tst:114960"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20666" test_ref="oval:org.mitre.oval:tst:114734"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16921" test_ref="oval:org.mitre.oval:tst:114739"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21044" test_ref="oval:org.mitre.oval:tst:114922"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16668" test_ref="oval:org.mitre.oval:tst:114145"/>
                <criteria operator="AND" comment="kb2957689 and kb2929437">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 11.0.9600.17041" test_ref="oval:org.mitre.oval:tst:113778"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17126" test_ref="oval:org.mitre.oval:tst:113991"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 8.1 / 2k12 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16668" test_ref="oval:org.mitre.oval:tst:114145"/>
                <criteria operator="AND" comment="kb2957689 and kb2919355">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 11.0.9600.17037" test_ref="oval:org.mitre.oval:tst:114108"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17126" test_ref="oval:org.mitre.oval:tst:113991"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24654" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability (CVE-2014-1815) - MS14-029</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-1815" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1815"/>
        <description>Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, as exploited in the wild in May 2014, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-0310.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-05-16T12:48:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-05-20T12:58:00.200-04:00">DRAFT</status_change>
            <status_change date="2014-06-09T04:01:20.501-04:00">INTERIM</status_change>
            <status_change date="2014-06-30T04:10:36.322-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24654 - extended definitions of OS are without SP checks" date="2014-07-28T18:08:00.084-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T18:10:09.713-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:02:35.687-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="ie6/2003/versions">
          <criteria operator="OR" comment="2003">
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5330" test_ref="oval:org.mitre.oval:tst:114173"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
        </criteria>
        <criteria operator="AND" comment="ie7">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="2003/vista/2008/">
            <criteria operator="AND" comment="2003/version">
              <criteria operator="OR" comment="either os">
                <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21385" test_ref="oval:org.mitre.oval:tst:113959"/>
            </criteria>
            <criteria operator="AND" comment="vista/2008/version">
              <criteria operator="OR" comment="either os">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="gdr/ldr">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19089" test_ref="oval:org.mitre.oval:tst:113982"/>
                <criteria operator="AND" comment="ldr range">
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23380" test_ref="oval:org.mitre.oval:tst:113848"/>
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="ie8">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vista/2008/win7/2008r2//versions">
            <criteria operator="AND" comment="vista/2008/versions">
              <criteria operator="OR" comment="either os">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="gdr/ldr">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19531" test_ref="oval:org.mitre.oval:tst:114050"/>
                <criteria operator="AND" comment="ldr range">
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23590" test_ref="oval:org.mitre.oval:tst:113957"/>
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="win7/2008 r2/version">
              <criteria operator="OR" comment="either os">
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="gdr/ldr">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18448" test_ref="oval:org.mitre.oval:tst:113593"/>
                <criteria operator="AND" comment="ldr range">
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22659" test_ref="oval:org.mitre.oval:tst:114134"/>
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="2003/version">
              <criteria operator="OR" comment="either os">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23590" test_ref="oval:org.mitre.oval:tst:113957"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="ie9">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16553" test_ref="oval:org.mitre.oval:tst:114230"/>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20664" test_ref="oval:org.mitre.oval:tst:113967"/>
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
            </criteria>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
        </criteria>
        <criteria operator="AND" comment="ie10">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16899" test_ref="oval:org.mitre.oval:tst:114075"/>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21026" test_ref="oval:org.mitre.oval:tst:114122"/>
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.20000" test_ref="oval:org.mitre.oval:tst:80523"/>
            </criteria>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
        </criteria>
        <criteria operator="AND" comment="IE11">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="either OS">
            <criteria operator="AND" comment="7/2008R2/versions">
              <criteria operator="OR" comment="7/2008R2">
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="either version">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16663" test_ref="oval:org.mitre.oval:tst:113817"/>
                <criteria operator="AND" comment="kb2964358 and kb2929437">
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17107" test_ref="oval:org.mitre.oval:tst:113245"/>
                  <criterion comment="Check for mshtml.dll version greater than or equal to 11.0.9600.17041" test_ref="oval:org.mitre.oval:tst:113778"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="8.1/2012R2/versions">
              <criteria operator="OR" comment="8.1/2012R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criteria operator="OR" comment="either version">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16663" test_ref="oval:org.mitre.oval:tst:113817"/>
                <criteria operator="AND" comment="kb2964358 and kb2919355">
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17107" test_ref="oval:org.mitre.oval:tst:113245"/>
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 11.0.9600.17037" test_ref="oval:org.mitre.oval:tst:114108"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24648" version="5" class="vulnerability">
      <metadata>
        <title>Vulnerability in .NET Framework could allow elevation of privilege - MS14-026</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft .NET Framework 1.1</product>
          <product>Microsoft .NET Framework 2.0</product>
          <product>Microsoft .NET Framework 3.5</product>
          <product>Microsoft .NET Framework 3.5.1</product>
          <product>Microsoft .NET Framework 4.0</product>
          <product>Microsoft .NET Framework 4.5</product>
          <product>Microsoft .NET Framework 4.5.1</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-1806" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1806"/>
        <description>The .NET Remoting implementation in Microsoft .NET Framework 1.1 SP1, 2.0 SP2, 3.5, 3.5.1, 4, 4.5, and 4.5.1 does not properly restrict memory access, which allows remote attackers to execute arbitrary code via vectors involving malformed objects, aka "TypeFilterLevel Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-05-16T15:16:57.075+05:30">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-05-20T12:53:00.420-04:00">DRAFT</status_change>
            <status_change date="2014-06-09T04:01:19.883-04:00">INTERIM</status_change>
            <status_change date="2014-06-30T04:10:35.843-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24648 - extended definitions of OS are without SP checks" date="2014-07-28T18:08:00.084-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T18:10:12.295-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:02:35.316-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment=".NET 1.1 and vulnerable file">
          <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
          <criterion comment="Check if the version of system.runtime.remoting.dll is less than 1.1.4322.2506" test_ref="oval:org.mitre.oval:tst:113757"/>
          <extend_definition comment="Microsoft .NET Framework 1.1 Service Pack 1 is Installed" definition_ref="oval:org.mitre.oval:def:1834"/>
        </criteria>
        <criteria operator="AND" comment=".NET 2.0 and  XP / server 2003">
          <criteria operator="OR" comment="Either OS">
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 2.0 Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6158"/>
          <criteria operator="OR" comment="Either file version">
            <criterion comment="Check if the version of system.runtime.remoting.dll is less than 2.0.50727.3659" test_ref="oval:org.mitre.oval:tst:113488"/>
            <criteria operator="AND" comment="ldr range for system.runtime.remoting.dll">
              <criterion comment="Check if the version of system.runtime.remoting.dll is less than 2.0.50727.7055" test_ref="oval:org.mitre.oval:tst:114151"/>
              <criterion comment="Check if the version of system.runtime.remoting.dll is greater than or equal to 2.0.50727.7000" test_ref="oval:org.mitre.oval:tst:114012"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment=".NET 2.0 and Vista / 2008">
          <criteria operator="OR" comment="Either OS">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 2.0 Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6158"/>
          <criteria operator="OR" comment="Either file version">
            <criterion comment="Check if the version of system.runtime.remoting.dll is less than 2.0.50727.4252" test_ref="oval:org.mitre.oval:tst:114129"/>
            <criteria operator="AND" comment="ldr range for system.runtime.remoting.dll">
              <criterion comment="Check if the version of system.runtime.remoting.dll is less than 2.0.50727.7057" test_ref="oval:org.mitre.oval:tst:114087"/>
              <criterion comment="Check if the version of system.runtime.remoting.dll is greater than or equal to 2.0.50727.7000" test_ref="oval:org.mitre.oval:tst:114012"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment=".NET 3.5 and Win 8 / server 2012">
          <criteria operator="OR" comment="Either OS">
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 3.5 SP1 is installed" definition_ref="oval:org.mitre.oval:def:12542"/>
          <criteria operator="OR" comment="Either file version">
            <criterion comment="Check if the version of the system.runtime.remoting.dll is less than 2.0.50727.6416" test_ref="oval:org.mitre.oval:tst:113918"/>
            <criteria operator="AND" comment="ldr range for system.runtime.remoting.dll">
              <criterion comment="Check if the version of system.runtime.remoting.dll is less than 2.0.50727.7055" test_ref="oval:org.mitre.oval:tst:114151"/>
              <criterion comment="Check if the version of system.runtime.remoting.dll is greater than or equal to 2.0.50727.7000" test_ref="oval:org.mitre.oval:tst:114012"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment=".NET and Win 8.1 / 2012 R2">
          <criteria operator="OR" comment="Either OS">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 3.5 SP1 is installed" definition_ref="oval:org.mitre.oval:def:12542"/>
          <criteria operator="OR" comment="Either file version">
            <criterion comment="Check if the version of system.runtime.remoting.dll is less than 2.0.50727.8003" test_ref="oval:org.mitre.oval:tst:114169"/>
            <criteria operator="AND" comment="ldr range for system.runtime.remoting.dll">
              <criterion comment="Check if the version of system.runtime.remoting.dll is less than 2.0.50727.8606" test_ref="oval:org.mitre.oval:tst:113903"/>
              <criterion comment="Check if the version of system.runtime.remoting.dll is greater than or equal to 2.0.50727.8600" test_ref="oval:org.mitre.oval:tst:114089"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment=".NET 3.5.1 and Win 7 / Server 2008 R2">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 3.5 SP1 is installed" definition_ref="oval:org.mitre.oval:def:12542"/>
          <criteria operator="OR" comment="Either file version">
            <criterion comment="Check if the version of system.runtime.remoting.dll is less than 2.0.50727.5483" test_ref="oval:org.mitre.oval:tst:114215"/>
            <criteria operator="AND" comment="ldr range for system.runtime.remoting.dll">
              <criterion comment="Check if the version of system.runtime.remoting.dll is less than 2.0.50727.7057" test_ref="oval:org.mitre.oval:tst:114087"/>
              <criterion comment="Check if the version of system.runtime.remoting.dll is greater than or equal to 2.0.50727.7000" test_ref="oval:org.mitre.oval:tst:114012"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment=".NET 4.0">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6749"/>
          <criteria operator="OR" comment="Either file version">
            <criterion comment="Check if the version of system.runtime.remoting.dll is less than 4.0.30319.1023" test_ref="oval:org.mitre.oval:tst:114080"/>
            <criteria operator="AND" comment="ldr range for system.runtime.remoting.dll">
              <criterion comment="Check if the version of system.runtime.remoting.dll is less than 4.0.30319.2036" test_ref="oval:org.mitre.oval:tst:114124"/>
              <criterion comment="Check if the version of system.runtime.remoting.dll is greater than or equal to 4.0.30319.2000" test_ref="oval:org.mitre.oval:tst:113636"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment=".NET 4.5/4.5.1 and Win Vista / Win 7 / server 2008 / Server 2008 R2">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Either .Net 4.5 / 4.5.1 version">
            <extend_definition comment="Microsoft .NET Framework 4.5 is installed" definition_ref="oval:org.mitre.oval:def:15925"/>
            <extend_definition comment="Microsoft .NET Framework 4.5.1 is installed" definition_ref="oval:org.mitre.oval:def:22275"/>
          </criteria>
          <criteria operator="OR" comment="Either file version">
            <criterion comment="Check if the version of system.runtime.remoting.dll is less than 4.0.30319.34108" test_ref="oval:org.mitre.oval:tst:114202"/>
            <criteria operator="AND" comment="ldr range for system.wen.dll">
              <criterion comment="Check if the version of system.runtime.remoting.dll is less than 4.0.30319.36106" test_ref="oval:org.mitre.oval:tst:114073"/>
              <criterion comment="Check if the version of system.runtime.remoting.dll is greater than or equal to 4.0.30319.36000" test_ref="oval:org.mitre.oval:tst:114135"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment=".NET and Win 8 /Server 2012">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Either .Net 4.5 / 4.5.1 version">
            <extend_definition comment="Microsoft .NET Framework 4.5 is installed" definition_ref="oval:org.mitre.oval:def:15925"/>
            <extend_definition comment="Microsoft .NET Framework 4.5.1 is installed" definition_ref="oval:org.mitre.oval:def:22275"/>
          </criteria>
          <criteria operator="OR" comment="Either file version">
            <criterion comment="Check if the version of system.runtime.remoting.dll is less than 4.0.30319.34107" test_ref="oval:org.mitre.oval:tst:113283"/>
            <criteria operator="AND" comment="ldr range for system.runtime.remoting.dll">
              <criterion comment="Check if the version of system.runtime.remoting.dll is less than 4.0.30319.36105" test_ref="oval:org.mitre.oval:tst:114065"/>
              <criterion comment="Check if the version of system.runtime.remoting.dll is greater than or equal to 4.0.30319.36000" test_ref="oval:org.mitre.oval:tst:114135"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment=".NET 4.5.1 / Win 8.1 / Server 2012 R2">
          <extend_definition comment="Microsoft .NET Framework 4.5.1 is installed" definition_ref="oval:org.mitre.oval:def:22275"/>
          <criteria operator="OR" comment="Either OS">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criteria operator="OR" comment="Either file version">
            <criterion comment="Check if the version of system.runtime.remoting.dll is less than 4.0.30319.34107" test_ref="oval:org.mitre.oval:tst:113283"/>
            <criteria operator="AND" comment="ldr range for mscorlib.dll">
              <criterion comment="Check if the version of system.runtime.remoting.dll is less than 4.0.30319.36115" test_ref="oval:org.mitre.oval:tst:114125"/>
              <criterion comment="Check if the version of system.runtime.remoting.dll is greater than or equal to 4.0.30319.36000" test_ref="oval:org.mitre.oval:tst:114135"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24618" version="3" class="vulnerability">
      <metadata>
        <title>Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization VirtualBox before 4.1.32, 4.2.24, and 4.3.10</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>VirtualBox</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-2441" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2441"/>
        <description>Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization VirtualBox before 4.1.32, 4.2.24, and 4.3.10 allows local users to affect confidentiality, integrity, and availability via vectors related to Graphics driver (WDDM) for Windows guests.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-04-17T08:31:03">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </submitted>
            <status_change date="2014-04-18T14:38:40.749-04:00">DRAFT</status_change>
            <status_change date="2014-05-05T04:00:24.278-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:06:28.149-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="VirtualBox is installed" definition_ref="oval:org.mitre.oval:def:11581"/>
        <criterion comment="Check if Oracle VM VirtualBox is installed" test_ref="oval:org.mitre.oval:tst:42006"/>
        <criteria operator="OR" comment="Check versions of VirtualBox">
          <criteria operator="AND" comment="Affected versions of VirtualBox">
            <criterion comment="Check if Oracle VM VirtualBox version is greater than or equals to 4.1.0" test_ref="oval:org.mitre.oval:tst:88836"/>
            <criterion comment="Check if Oracle VM VirtualBox version is less than  or equals to 4.1.30" test_ref="oval:org.mitre.oval:tst:113796"/>
          </criteria>
          <criteria operator="AND" comment="Affected versions of VirtualBox">
            <criterion comment="Check if Oracle VM VirtualBox version is greater than or equals to 4.2.0" test_ref="oval:org.mitre.oval:tst:99857"/>
            <criterion comment="Check if Oracle VM VirtualBox version is less than  or equals to 4.2.22" test_ref="oval:org.mitre.oval:tst:113462"/>
          </criteria>
          <criteria operator="AND" comment="Affected versions of VirtualBox">
            <criterion comment="Check if Oracle VM VirtualBox version is greater than or equals to 4.3.0" test_ref="oval:org.mitre.oval:tst:100120"/>
            <criterion comment="Check if Oracle VM VirtualBox version is less than  or equals to 4.3.8" test_ref="oval:org.mitre.oval:tst:113616"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24592" version="5" class="vulnerability">
      <metadata>
        <title>Ancillary Function Driver Elevation of Privilege Vulnerability - CVE-2014-1767 (MS14-040)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 7</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-1767" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1767"/>
        <description>Double free vulnerability in the Ancillary Function Driver (AFD) in afd.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges via a crafted application, aka "Ancillary Function Driver Elevation of Privilege Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-07-11T13:00:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-07-11T11:51:49.746-04:00">DRAFT</status_change>
            <status_change date="2014-07-28T04:00:24.303-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:02:33.385-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Server 2003 x86,x64/ia64 SP2">
          <criteria operator="OR" comment="Windows Server 2003 x86,x64/ia64 SP2">
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
          </criteria>
          <criterion comment="Check if the version of Afd.sys is less than 5.2.3790.5358" test_ref="oval:org.mitre.oval:tst:115663"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows Vista x86,x64 SP2, Server 2008 x86,x64/ia64 SP2">
          <criteria operator="OR" comment="Windows Vista x86,x64 SP2, Server 2008 x86,x64/ia64">
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
            <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
          </criteria>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="Check if the version of Afd.sys is less than 6.0.6002.19115" test_ref="oval:org.mitre.oval:tst:115682"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="Check if the version of afd.sys is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:87004"/>
              <criterion comment="Check if the version of Afd.sys is less than 6.0.6002.23414" test_ref="oval:org.mitre.oval:tst:115447"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Microsoft Windows 7 x64 SP1, Server 2008 R2 x64/ia64 SP1">
          <criteria operator="OR" comment="Microsoft Windows 7 x86,x64 SP1, Server 2008 R2 x64/ia64 SP1">
            <extend_definition comment="Microsoft Windows 7 x64 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12627"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12567"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12583"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12292"/>
          </criteria>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="Check if the version of Afd.sys is less than 6.1.7601.18489" test_ref="oval:org.mitre.oval:tst:115701"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="The version of afd.sys is greater than or equal to 6.1.7601.21000" test_ref="oval:org.mitre.oval:tst:42554"/>
              <criterion comment="Check if the version of Afd.sys is less than 6.1.7601.22705" test_ref="oval:org.mitre.oval:tst:115620"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8 / 2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of Afd.sys is less than 6.2.9200.17014" test_ref="oval:org.mitre.oval:tst:114833"/>
            <criteria operator="AND" comment="Check for LDR range">
              <criterion comment="Check if the version of Afd.sys is less than 6.2.9200.21133" test_ref="oval:org.mitre.oval:tst:115622"/>
              <criterion comment="Check if the version of afd.sys is greater than or equal to 6.2.9200.20000" test_ref="oval:org.mitre.oval:tst:87102"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="8.1/2012 R2 and vulnerable version">
          <criteria operator="OR" comment="8.1/ 2012 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of Afd.sys is less than 6.3.9600.16668" test_ref="oval:org.mitre.oval:tst:115522"/>
            <criteria operator="AND" comment="Check for LDR range">
              <criterion comment="Check if the version of Afd.sys is less than 6.3.9600.17194" test_ref="oval:org.mitre.oval:tst:115534"/>
              <criterion comment="Check if the version of Afd.sys is greater than or equal to 6.3.9600.17088" test_ref="oval:org.mitre.oval:tst:115711"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24580" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability (CVE-2014-1803) - MS14-035</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-1803" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1803"/>
        <description>Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-0282, CVE-2014-1775, CVE-2014-1779, CVE-2014-1799, and CVE-2014-2757.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-06-16T09:23:20">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-06-20T11:22:20.327-04:00">DRAFT</status_change>
            <status_change date="2014-07-07T04:01:16.363-04:00">INTERIM</status_change>
            <status_change date="2014-07-28T04:00:23.881-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24580 - Updated to remove SP checks." date="2014-08-07T14:56:00.647-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-08-07T14:58:16.327-04:00">INTERIM</status_change>
            <status_change date="2014-08-25T04:00:30.405-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5341" test_ref="oval:org.mitre.oval:tst:114964"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21389" test_ref="oval:org.mitre.oval:tst:114956"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista/2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19098" test_ref="oval:org.mitre.oval:tst:114438"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23389" test_ref="oval:org.mitre.oval:tst:114853"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23598" test_ref="oval:org.mitre.oval:tst:114669"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19539" test_ref="oval:org.mitre.oval:tst:114916"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23598" test_ref="oval:org.mitre.oval:tst:114669"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18472" test_ref="oval:org.mitre.oval:tst:114770"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22686" test_ref="oval:org.mitre.oval:tst:114915"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16555" test_ref="oval:org.mitre.oval:tst:114960"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20666" test_ref="oval:org.mitre.oval:tst:114734"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16921" test_ref="oval:org.mitre.oval:tst:114739"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21044" test_ref="oval:org.mitre.oval:tst:114922"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16668" test_ref="oval:org.mitre.oval:tst:114145"/>
                <criteria operator="AND" comment="kb2957689 and kb2929437">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 11.0.9600.17041" test_ref="oval:org.mitre.oval:tst:113778"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17126" test_ref="oval:org.mitre.oval:tst:113991"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 8.1 / 2k12 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16668" test_ref="oval:org.mitre.oval:tst:114145"/>
                <criteria operator="AND" comment="kb2957689 and kb2919355">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 11.0.9600.17037" test_ref="oval:org.mitre.oval:tst:114108"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17126" test_ref="oval:org.mitre.oval:tst:113991"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24572" version="3" class="vulnerability">
      <metadata>
        <title>Windows Shell File Association Vulnerability - CVE-2014-1807 (MS14-027)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-1807" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1807"/>
        <description>The ShellExecute API in Windows Shell in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 does not properly implement file associations, which allows local users to gain privileges via a crafted application, as exploited in the wild in May 2014, aka "Windows Shell File Association Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-05-16T19:28:31">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-05-20T12:54:32.634-04:00">DRAFT</status_change>
            <status_change date="2014-06-09T04:01:00.973-04:00">INTERIM</status_change>
            <status_change date="2014-06-30T04:10:24.183-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="2K3 and vulnerable file version">
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
          </criteria>
          <criterion comment="Check if the version of shlwapi.dll is less than 6.0.3790.5318" test_ref="oval:org.mitre.oval:tst:114095"/>
        </criteria>
        <criteria operator="AND" comment="Vista / 2K8 and vulnerable file versions">
          <criteria operator="OR" comment="Vista / 2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
            <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of shell32.dll is less than 6.0.6002.19070" test_ref="oval:org.mitre.oval:tst:114063"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of shell32.dll is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:113981"/>
              <criterion comment="Check if the version of shell32.dll is less than 6.0.6002.23360" test_ref="oval:org.mitre.oval:tst:113937"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="&quot;Windows 7 / 2008 R2 and vulnerable file version">
          <criteria operator="OR" comment="Win 7 / 2k8 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12292"/>
            <extend_definition comment="Microsoft Windows 7 x64 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12627"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12567"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12583"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of shell32.dll is less than 6.1.7601.18429" test_ref="oval:org.mitre.oval:tst:113790"/>
            <criteria operator="AND" comment="Check for LDR range">
              <criterion comment="Check if the version of shell32.dll is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:113444"/>
              <criterion comment="Check if the version of shell32.dll is less than 6.1.7601.22639" test_ref="oval:org.mitre.oval:tst:114152"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8 / Server 2012 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable range">
            <criterion comment="Check if the version of shell32.dll is less than 6.2.9200.16882" test_ref="oval:org.mitre.oval:tst:114153"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of shell32.dll is greater than or equal to 6.2.9200.20000" test_ref="oval:org.mitre.oval:tst:114092"/>
              <criterion comment="Check if the version of shell32.dll is less than 6.2.9200.21000" test_ref="oval:org.mitre.oval:tst:114163"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1 / 2k12 R2 and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of shell32.dll is less than 6.3.9600.17083" test_ref="oval:org.mitre.oval:tst:113863"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24566" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability (CVE-2014-1794) - MS14-035</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-1794" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1794"/>
        <description>Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-1772, CVE-2014-1780, CVE-2014-1797, CVE-2014-1802, CVE-2014-2756, CVE-2014-2763, CVE-2014-2764, CVE-2014-2769, and CVE-2014-2771.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-06-16T09:23:20">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-06-20T11:22:55.166-04:00">DRAFT</status_change>
            <status_change date="2014-07-07T04:01:16.230-04:00">INTERIM</status_change>
            <status_change date="2014-07-28T04:00:22.952-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24566 - Updated to remove SP checks." date="2014-08-07T14:55:00.409-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-08-07T14:56:51.752-04:00">INTERIM</status_change>
            <status_change date="2014-08-25T04:00:29.882-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16921" test_ref="oval:org.mitre.oval:tst:114739"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21044" test_ref="oval:org.mitre.oval:tst:114922"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16668" test_ref="oval:org.mitre.oval:tst:114145"/>
                <criteria operator="AND" comment="kb2957689 and kb2929437">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 11.0.9600.17041" test_ref="oval:org.mitre.oval:tst:113778"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17126" test_ref="oval:org.mitre.oval:tst:113991"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 8.1 / 2k12 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16668" test_ref="oval:org.mitre.oval:tst:114145"/>
                <criteria operator="AND" comment="kb2957689 and kb2919355">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 11.0.9600.17037" test_ref="oval:org.mitre.oval:tst:114108"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17126" test_ref="oval:org.mitre.oval:tst:113991"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24506" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability (CVE-2014-1778) - MS14-035</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-1778" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1778"/>
        <description>Microsoft Internet Explorer 8 through 11 allows remote attackers to execute arbitrary web script with increased privileges via unspecified vectors, aka "Internet Explorer Elevation of Privilege Vulnerability," a different vulnerability than CVE-2014-2777.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-06-16T09:23:20">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-06-20T11:21:52.275-04:00">DRAFT</status_change>
            <status_change date="2014-07-07T04:01:15.482-04:00">INTERIM</status_change>
            <status_change date="2014-07-28T04:00:21.335-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24506 - Updated to remove SP checks." date="2014-08-07T14:55:00.409-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-08-07T14:56:52.193-04:00">INTERIM</status_change>
            <status_change date="2014-08-25T04:00:28.988-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23598" test_ref="oval:org.mitre.oval:tst:114669"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19539" test_ref="oval:org.mitre.oval:tst:114916"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23598" test_ref="oval:org.mitre.oval:tst:114669"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18472" test_ref="oval:org.mitre.oval:tst:114770"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22686" test_ref="oval:org.mitre.oval:tst:114915"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16555" test_ref="oval:org.mitre.oval:tst:114960"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20666" test_ref="oval:org.mitre.oval:tst:114734"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16921" test_ref="oval:org.mitre.oval:tst:114739"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21044" test_ref="oval:org.mitre.oval:tst:114922"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16668" test_ref="oval:org.mitre.oval:tst:114145"/>
                <criteria operator="AND" comment="kb2957689 and kb2929437">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 11.0.9600.17041" test_ref="oval:org.mitre.oval:tst:113778"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17126" test_ref="oval:org.mitre.oval:tst:113991"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 8.1 / 2k12 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16668" test_ref="oval:org.mitre.oval:tst:114145"/>
                <criteria operator="AND" comment="kb2957689 and kb2919355">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 11.0.9600.17037" test_ref="oval:org.mitre.oval:tst:114108"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17126" test_ref="oval:org.mitre.oval:tst:113991"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24496" version="6" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability - CVE-2014-2795 (MS14-037)</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-2795" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2795"/>
        <description>Microsoft Internet Explorer 8 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-2789, CVE-2014-2798, and CVE-2014-2804.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-07-11T08:33:30">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-07-11T11:47:57.553-04:00">DRAFT</status_change>
            <status_change date="2014-07-28T04:00:20.727-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24496 - Updated to remove SP checks." date="2014-08-07T14:56:00.647-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-08-25T04:00:28.341-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23603" test_ref="oval:org.mitre.oval:tst:115559"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19543" test_ref="oval:org.mitre.oval:tst:114962"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23603" test_ref="oval:org.mitre.oval:tst:115559"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18487" test_ref="oval:org.mitre.oval:tst:115377"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22703" test_ref="oval:org.mitre.oval:tst:115320"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16561" test_ref="oval:org.mitre.oval:tst:114824"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20672" test_ref="oval:org.mitre.oval:tst:115308"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.17028" test_ref="oval:org.mitre.oval:tst:115430"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21145" test_ref="oval:org.mitre.oval:tst:115571"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16672" test_ref="oval:org.mitre.oval:tst:115696"/>
                <criteria operator="AND" comment="kb2957689 and kb2929437">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 11.0.9600.17041" test_ref="oval:org.mitre.oval:tst:113778"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17207" test_ref="oval:org.mitre.oval:tst:115689"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 8.1 / 2k12 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16672" test_ref="oval:org.mitre.oval:tst:115696"/>
                <criteria operator="AND" comment="kb2957689 and kb2919355">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 11.0.9600.17037" test_ref="oval:org.mitre.oval:tst:114108"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17207" test_ref="oval:org.mitre.oval:tst:115689"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24480" version="3" class="vulnerability">
      <metadata>
        <title>SharePoint XSS Vulnerability (CVE-2014-1754) - MS14-022</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft SharePoint Foundation 2013</product>
          <product>Microsoft SharePoint Server 2013</product>
          <product>Microsoft Office Web Apps Server 2013</product>
          <product>Microsoft SharePoint Server 2013 Client Components SDK</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-1754" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1754"/>
        <description>Cross-site scripting (XSS) vulnerability in Microsoft SharePoint Server 2013 Gold and SP1, SharePoint Foundation 2013 Gold and SP1, Office Web Apps Server 2013 Gold and SP1, and SharePoint Server 2013 Client Components SDK allows remote attackers to inject arbitrary web script or HTML via a crafted request, aka "SharePoint XSS Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-05-26T14:12:20">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-05-27T13:27:08.488-04:00">DRAFT</status_change>
            <status_change date="2014-06-16T04:00:11.888-04:00">INTERIM</status_change>
            <status_change date="2014-07-07T04:01:15.125-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="foundation 2013/version">
          <criterion comment="Check if the version of Microsoft.Office.Server.Msg.dll is less than 15.0.4514.1000" test_ref="oval:org.mitre.oval:tst:114603"/>
          <criteria operator="OR" comment="2013/sp1">
            <extend_definition comment="Microsoft SharePoint Server 2013 is installed" definition_ref="oval:org.mitre.oval:def:16325"/>
            <extend_definition comment="Microsoft SharePoint Server 2013 SP1 is installed" definition_ref="oval:org.mitre.oval:def:24462"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="sharepoint foundation 2013/version">
          <criteria operator="OR" comment="2013/sp1">
            <extend_definition comment="Microsoft SharePoint Foundation 2013 is installed" definition_ref="oval:org.mitre.oval:def:19090"/>
            <extend_definition comment="Microsoft SharePoint Foundation 2013 SP1 is installed" definition_ref="oval:org.mitre.oval:def:24685"/>
          </criteria>
          <criteria operator="OR" comment="either versions">
            <criterion comment="Check if the version of wsssetup.dll is less than 15.0.4615.1000" test_ref="oval:org.mitre.oval:tst:113960"/>
            <criterion comment="Check if the version of wsetupui.dll is less than 15.0.4561.1000" test_ref="oval:org.mitre.oval:tst:114600"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="web apps server 2013/version">
          <criteria operator="OR" comment="2013/sp1">
            <extend_definition comment="Microsoft Office Web Apps Server 2013 is installed" definition_ref="oval:org.mitre.oval:def:22312"/>
            <extend_definition comment="Microsoft Office Web Apps Server 2013 SP1 is installed" definition_ref="oval:org.mitre.oval:def:24530"/>
          </criteria>
          <criterion comment="Check if the version of msoserver.dll is less than 15.0.4615.1000" test_ref="oval:org.mitre.oval:tst:114430"/>
        </criteria>
        <criteria operator="AND" comment="SharePoint Server 2013 Client Components SDK/version">
          <extend_definition comment="Microsoft SharePoint Server 2013 Client Components SDK is installed" definition_ref="oval:org.mitre.oval:def:24752"/>
          <criterion comment="Check if the version of Microsoft.sharepoint.client.dll is less than 15.0.4609.1000" test_ref="oval:org.mitre.oval:tst:114066"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24752" version="3" class="inventory">
      <metadata>
        <title>Microsoft SharePoint Server 2013 Client Components SDK is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <product>Microsoft SharePoint Server 2013 Client Components SDK</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:sharepoint_server_client_components_sdk:2013"/>
        <description>Microsoft SharePoint Server 2013 Client Components SDK is installed</description>
        <oval_repository>
          <dates>
            <submitted date="2014-05-26T16:15:48">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-05-27T13:27:05.214-04:00">DRAFT</status_change>
            <status_change date="2014-06-16T04:00:15.775-04:00">INTERIM</status_change>
            <status_change date="2014-07-07T04:01:19.339-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="Check if Microsoft SharePoint Server 2013 Client Components SDK is installed" test_ref="oval:org.mitre.oval:tst:114587"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24685" version="5" class="inventory">
      <metadata>
        <title>Microsoft SharePoint Foundation 2013 SP1 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft SharePoint Foundation 2013</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:sharepoint_foundation:2013:sp1"/>
        <description>Microsoft SharePoint Foundation 2013 SP1 is installed</description>
        <oval_repository>
          <dates>
            <submitted date="2014-05-26T14:12:20">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-05-27T13:27:04.107-04:00">DRAFT</status_change>
            <status_change date="2014-06-16T04:00:13.760-04:00">INTERIM</status_change>
            <status_change date="2014-07-07T04:01:18.247-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:39142 - In some &quot;pattern match&quot; strings added &quot;\&quot; before &quot;.&quot; to clarify if &quot;point&quot; or &quot;any symbol&quot; needed." date="2014-07-28T18:11:00.493-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-07-28T18:14:45.534-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:02:43.221-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="Check if Sharepoint server 2013 SP1 is installed" test_ref="oval:org.mitre.oval:tst:114158"/>
        <extend_definition comment="Microsoft SharePoint Foundation 2013 is installed" definition_ref="oval:org.mitre.oval:def:19090"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24530" version="6" class="inventory">
      <metadata>
        <title>Microsoft Office Web Apps Server 2013 SP1 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Office Web Apps Server 2013</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:office_web_apps:2013:sp1"/>
        <description>Microsoft Office Web Apps Server 2013 SP1 is installed</description>
        <oval_repository>
          <dates>
            <submitted date="2014-05-26T14:12:20">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-05-27T13:27:04.569-04:00">DRAFT</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:39205 - regular expression fixes" date="2014-06-10T14:50:00.707-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-06-30T04:10:22.150-04:00">INTERIM</status_change>
            <status_change date="2014-07-21T04:01:22.543-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:39205 - In some &quot;pattern match&quot; strings added &quot;\&quot; before &quot;.&quot; to clarify if &quot;point&quot; or &quot;any symbol&quot; needed." date="2014-07-28T18:11:00.493-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-07-28T18:12:35.894-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:02:32.248-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="Check if Web Apps Server 2013 SP1 is installed" test_ref="oval:org.mitre.oval:tst:114300"/>
        <extend_definition comment="Microsoft Office Web Apps Server 2013 is installed" definition_ref="oval:org.mitre.oval:def:22312"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24462" version="5" class="inventory">
      <metadata>
        <title>Microsoft SharePoint Server 2013 SP1 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft SharePoint Server 2013</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:sharepoint_server:2013:sp1"/>
        <description>Microsoft SharePoint Server 2013 SP1 is installed</description>
        <oval_repository>
          <dates>
            <submitted date="2014-05-26T14:12:20">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-05-27T13:27:03.977-04:00">DRAFT</status_change>
            <status_change date="2014-06-16T04:00:11.763-04:00">INTERIM</status_change>
            <status_change date="2014-07-07T04:01:14.552-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:39142 - In some &quot;pattern match&quot; strings added &quot;\&quot; before &quot;.&quot; to clarify if &quot;point&quot; or &quot;any symbol&quot; needed." date="2014-07-28T18:11:00.493-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-07-28T18:14:45.577-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:02:31.164-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="Check if Sharepoint server 2013 SP1 is installed" test_ref="oval:org.mitre.oval:tst:114158"/>
        <extend_definition comment="Microsoft SharePoint Server 2013 is installed" definition_ref="oval:org.mitre.oval:def:16325"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22312" version="3" class="inventory">
      <metadata>
        <title>Microsoft Office Web Apps Server 2013 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <product>Microsoft Office Web Apps Server 2013</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:office_web_apps:2013"/>
        <description>Microsoft Office Web Apps Server 2013 is installed</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-17T14:16:01">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-01-21T17:03:41.194-05:00">DRAFT</status_change>
            <status_change date="2014-02-10T04:00:25.770-05:00">INTERIM</status_change>
            <status_change date="2014-03-03T04:01:05.741-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="Check if Msoserver.dll is present" test_ref="oval:org.mitre.oval:tst:99831"/>
        <criterion comment="Check for the existence of SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Office15.WacServer" test_ref="oval:org.mitre.oval:tst:100108"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24476" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer memory corruption vulnerability (CVE-2014-0310) - MS14-029</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-0310" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0310"/>
        <description>Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-1815.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-05-16T12:48:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-05-20T12:58:03.253-04:00">DRAFT</status_change>
            <status_change date="2014-06-09T04:00:44.040-04:00">INTERIM</status_change>
            <status_change date="2014-06-30T04:10:20.289-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24476 - extended definitions of OS are without SP checks" date="2014-07-28T18:08:00.084-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T18:10:11.241-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:02:31.294-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="ie6/2003/versions">
          <criteria operator="OR" comment="2003">
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5330" test_ref="oval:org.mitre.oval:tst:114173"/>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
        </criteria>
        <criteria operator="AND" comment="ie7">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="2003/vista/2008/">
            <criteria operator="AND" comment="2003/version">
              <criteria operator="OR" comment="either os">
                <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21385" test_ref="oval:org.mitre.oval:tst:113959"/>
            </criteria>
            <criteria operator="AND" comment="vista/2008/version">
              <criteria operator="OR" comment="either os">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="gdr/ldr">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19089" test_ref="oval:org.mitre.oval:tst:113982"/>
                <criteria operator="AND" comment="ldr range">
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23380" test_ref="oval:org.mitre.oval:tst:113848"/>
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="ie8">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vista/2008/win7/2008r2//versions">
            <criteria operator="AND" comment="vista/2008/versions">
              <criteria operator="OR" comment="either os">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="gdr/ldr">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19531" test_ref="oval:org.mitre.oval:tst:114050"/>
                <criteria operator="AND" comment="ldr range">
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23590" test_ref="oval:org.mitre.oval:tst:113957"/>
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="win7/2008 r2/version">
              <criteria operator="OR" comment="either os">
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="gdr/ldr">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18448" test_ref="oval:org.mitre.oval:tst:113593"/>
                <criteria operator="AND" comment="ldr range">
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22659" test_ref="oval:org.mitre.oval:tst:114134"/>
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="2003/version">
              <criteria operator="OR" comment="either os">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23590" test_ref="oval:org.mitre.oval:tst:113957"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="ie9">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16553" test_ref="oval:org.mitre.oval:tst:114230"/>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20664" test_ref="oval:org.mitre.oval:tst:113967"/>
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
            </criteria>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
        </criteria>
        <criteria operator="AND" comment="ie10">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16899" test_ref="oval:org.mitre.oval:tst:114075"/>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21026" test_ref="oval:org.mitre.oval:tst:114122"/>
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.20000" test_ref="oval:org.mitre.oval:tst:80523"/>
            </criteria>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
        </criteria>
        <criteria operator="AND" comment="IE11">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="either OS">
            <criteria operator="AND" comment="7/2008R2/versions">
              <criteria operator="OR" comment="7/2008R2">
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="either version">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16663" test_ref="oval:org.mitre.oval:tst:113817"/>
                <criteria operator="AND" comment="kb2964358 and kb2929437">
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17107" test_ref="oval:org.mitre.oval:tst:113245"/>
                  <criterion comment="Check for mshtml.dll version greater than or equal to 11.0.9600.17041" test_ref="oval:org.mitre.oval:tst:113778"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="8.1/2012R2/versions">
              <criteria operator="OR" comment="8.1/2012R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criteria operator="OR" comment="either version">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16663" test_ref="oval:org.mitre.oval:tst:113817"/>
                <criteria operator="AND" comment="kb2964358 and kb2919355">
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17107" test_ref="oval:org.mitre.oval:tst:113245"/>
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 11.0.9600.17037" test_ref="oval:org.mitre.oval:tst:114108"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24465" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability (CVE-2014-2763) - MS14-035</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-2763" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2763"/>
        <description>Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-1772, CVE-2014-1780, CVE-2014-1794, CVE-2014-1797, CVE-2014-1802, CVE-2014-2756, CVE-2014-2764, CVE-2014-2769, and CVE-2014-2771.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-06-16T09:23:20">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-06-20T11:22:07.619-04:00">DRAFT</status_change>
            <status_change date="2014-07-07T04:01:14.685-04:00">INTERIM</status_change>
            <status_change date="2014-07-28T04:00:19.791-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24465 - Updated to remove SP checks." date="2014-08-07T14:55:00.409-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-08-07T14:56:52.572-04:00">INTERIM</status_change>
            <status_change date="2014-08-25T04:00:27.232-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16921" test_ref="oval:org.mitre.oval:tst:114739"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21044" test_ref="oval:org.mitre.oval:tst:114922"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16668" test_ref="oval:org.mitre.oval:tst:114145"/>
                <criteria operator="AND" comment="kb2957689 and kb2929437">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 11.0.9600.17041" test_ref="oval:org.mitre.oval:tst:113778"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17126" test_ref="oval:org.mitre.oval:tst:113991"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 8.1 / 2k12 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16668" test_ref="oval:org.mitre.oval:tst:114145"/>
                <criteria operator="AND" comment="kb2957689 and kb2919355">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 11.0.9600.17037" test_ref="oval:org.mitre.oval:tst:114108"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17126" test_ref="oval:org.mitre.oval:tst:113991"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24442" version="6" class="vulnerability">
      <metadata>
        <title>Windows file handling vulnerability - CVE-2014-0315 (MS14-019)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-0315" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0315"/>
        <description>Untrusted search path vulnerability in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges via a Trojan horse cmd.exe file in the current working directory, as demonstrated by a directory that contains a .bat or .cmd file, aka "Windows File Handling Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-04-10T12:04:05">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-04-10T14:51:40.124-04:00">DRAFT</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:20161 - MS14-019 for the month of Apr 2014" date="2014-04-10T14:44:00.532-04:00">
              <contributor organization="SecPod Technologies">Pooja Shetty</contributor>
            </modified>
            <status_change date="2014-04-28T04:07:36.006-04:00">INTERIM</status_change>
            <status_change date="2014-05-19T04:00:15.717-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Win XP X86 + vulnerable file version">
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <criterion comment="Check if the version of kernel32.dll is less than 5.1.2600.6532" test_ref="oval:org.mitre.oval:tst:113820"/>
        </criteria>
        <criteria operator="AND" comment="XP X64 + vulnerable file version">
          <criteria operator="OR" comment="XP X64 / 2k3">
            <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
          </criteria>
          <criterion comment="Check if the version of kernel32.dll is less than 5.2.3790.5295" test_ref="oval:org.mitre.oval:tst:113436"/>
        </criteria>
        <criteria operator="AND" comment="Vista / 2k8 + vulnerable file version">
          <criteria operator="OR" comment="Vista / 2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
            <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
          </criteria>
          <criteria operator="OR" comment="LDR/GDR">
            <criterion comment="Check if the version of kernel32.dll is less than 6.0.6002.19034" test_ref="oval:org.mitre.oval:tst:113783"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of kernel32.dll is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:113560"/>
              <criterion comment="Check if the version of kernel32.dll is less than 6.0.6002.23323" test_ref="oval:org.mitre.oval:tst:113872"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / R2 SP1 + vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2 SP1">
            <extend_definition comment="Microsoft Windows 7 (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12292"/>
            <extend_definition comment="Microsoft Windows 7 x64 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12627"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12567"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12583"/>
          </criteria>
          <criteria operator="OR" comment="Check for LDR/GDR">
            <criterion comment="Check if the version of kernel32.dll is less than 6.1.7601.18409" test_ref="oval:org.mitre.oval:tst:113150"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of kernel32.dll is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:113836"/>
              <criterion comment="Check if the version of kernel32.dll is less than 6.1.7601.22616" test_ref="oval:org.mitre.oval:tst:113597"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8 / 2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of kernel32.dll is less than 6.2.9200.16815" test_ref="oval:org.mitre.oval:tst:113503"/>
            <criteria operator="AND" comment="Check for LDR range">
              <criterion comment="Check if the version of kernel32.dll is greater than or equal to 6.2.9200.20000" test_ref="oval:org.mitre.oval:tst:112923"/>
              <criterion comment="Check if the version of kernel32.dll is less than 6.2.9200.20935" test_ref="oval:org.mitre.oval:tst:113794"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="8.1/2012 R2 and vulnerable version">
          <criteria operator="OR" comment="8.1/ 2012 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of kernel32.dll is less than 6.3.9600.16656" test_ref="oval:org.mitre.oval:tst:113804"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24372" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability (CVE-2014-1797) - MS14-035</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-1797" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1797"/>
        <description>Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-1772, CVE-2014-1780, CVE-2014-1794, CVE-2014-1802, CVE-2014-2756, CVE-2014-2763, CVE-2014-2764, CVE-2014-2769, and CVE-2014-2771.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-06-16T09:23:20">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-06-20T11:23:00.130-04:00">DRAFT</status_change>
            <status_change date="2014-07-07T04:01:12.252-04:00">INTERIM</status_change>
            <status_change date="2014-07-28T04:00:18.473-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24372 - Updated to remove SP checks." date="2014-08-07T14:55:00.409-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-08-07T14:56:53.889-04:00">INTERIM</status_change>
            <status_change date="2014-08-25T04:00:26.811-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16921" test_ref="oval:org.mitre.oval:tst:114739"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21044" test_ref="oval:org.mitre.oval:tst:114922"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16668" test_ref="oval:org.mitre.oval:tst:114145"/>
                <criteria operator="AND" comment="kb2957689 and kb2929437">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 11.0.9600.17041" test_ref="oval:org.mitre.oval:tst:113778"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17126" test_ref="oval:org.mitre.oval:tst:113991"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 8.1 / 2k12 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16668" test_ref="oval:org.mitre.oval:tst:114145"/>
                <criteria operator="AND" comment="kb2957689 and kb2919355">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 11.0.9600.17037" test_ref="oval:org.mitre.oval:tst:114108"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17126" test_ref="oval:org.mitre.oval:tst:113991"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24328" version="3" class="vulnerability">
      <metadata>
        <title>Group Policy Preferences Password Elevation of Privilege Vulnerability - CVE-2014-1812 (MS14-025)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-1812" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1812"/>
        <description>The Group Policy implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 does not properly handle distribution of passwords, which allows remote authenticated users to obtain sensitive credential information and consequently gain privileges by leveraging access to the SYSVOL share, as exploited in the wild in May 2014, aka "Group Policy Preferences Password Elevation of Privilege Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-05-16T13:00:04">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-05-20T12:51:25.813-04:00">DRAFT</status_change>
            <status_change date="2014-06-09T04:00:34.612-04:00">INTERIM</status_change>
            <status_change date="2014-06-30T04:10:07.301-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="2k8/Vista and vulnerable file version">
          <criteria operator="OR" comment="2k8 / Vista">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
            <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of gpme.dll is less than 6.0.6002.19047" test_ref="oval:org.mitre.oval:tst:114027"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of gpme.dll is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:114197"/>
              <criterion comment="Check if the version of gpme.dll is less than 6.0.6002.23339" test_ref="oval:org.mitre.oval:tst:114149"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / R2 and vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12292"/>
            <extend_definition comment="Microsoft Windows 7 x64 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12627"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12567"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12583"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of gpme.dll is less than 6.1.7601.17514" test_ref="oval:org.mitre.oval:tst:113921"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of gpme.dll is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:113430"/>
              <criterion comment="Check if the version of gpme.dll is less than 6.1.7601.22605" test_ref="oval:org.mitre.oval:tst:114131"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Windows 8/ 2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criterion comment="Check if the version of gpme.dll is less than 6.2.9200.16384" test_ref="oval:org.mitre.oval:tst:113789"/>
        </criteria>
        <criteria operator="AND" comment="Win 8.1 or Server 2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1/ 2k12">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable range">
            <criterion comment="Check if the version of gppref.dll is less than 6.3.9600.16660" test_ref="oval:org.mitre.oval:tst:114190"/>
            <criteria operator="AND" comment="Check for version if KB2919355 is installed">
              <criterion comment="Check if the version of gppref.dll is greater than or equal to 6.3.9600.17039" test_ref="oval:org.mitre.oval:tst:114228"/>
              <criterion comment="Check if the version of gppref.dll is less than 6.3.9600.17041" test_ref="oval:org.mitre.oval:tst:114074"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24252" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability (CVE-2014-2775) - MS14-035</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-2775" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2775"/>
        <description>Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-1773, CVE-2014-1783, CVE-2014-1784, CVE-2014-1786, CVE-2014-1795, CVE-2014-1805, CVE-2014-2758, CVE-2014-2759, CVE-2014-2765, and CVE-2014-2766.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-06-16T09:23:20">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-06-20T11:21:56.297-04:00">DRAFT</status_change>
            <status_change date="2014-07-07T04:01:08.250-04:00">INTERIM</status_change>
            <status_change date="2014-07-28T04:00:16.629-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24252 - Updated to remove SP checks." date="2014-08-07T14:55:00.409-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-08-07T14:56:50.278-04:00">INTERIM</status_change>
            <status_change date="2014-08-25T04:00:25.913-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16555" test_ref="oval:org.mitre.oval:tst:114960"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20666" test_ref="oval:org.mitre.oval:tst:114734"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16921" test_ref="oval:org.mitre.oval:tst:114739"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21044" test_ref="oval:org.mitre.oval:tst:114922"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16668" test_ref="oval:org.mitre.oval:tst:114145"/>
                <criteria operator="AND" comment="kb2957689 and kb2929437">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 11.0.9600.17041" test_ref="oval:org.mitre.oval:tst:113778"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17126" test_ref="oval:org.mitre.oval:tst:113991"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 8.1 / 2k12 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16668" test_ref="oval:org.mitre.oval:tst:114145"/>
                <criteria operator="AND" comment="kb2957689 and kb2919355">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 11.0.9600.17037" test_ref="oval:org.mitre.oval:tst:114108"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17126" test_ref="oval:org.mitre.oval:tst:113991"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24170" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability (CVE-2014-1770) - MS14-035</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-1770" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1770"/>
        <description>Use-after-free vulnerability in Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code via crafted JavaScript code that interacts improperly with a CollectGarbage function call on a CMarkup object allocated by the CMarkup::CreateInitialMarkup function.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-06-16T09:23:20">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-06-20T11:22:30.522-04:00">DRAFT</status_change>
            <status_change date="2014-07-07T04:01:05.287-04:00">INTERIM</status_change>
            <status_change date="2014-07-28T04:00:15.020-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24170 - Updated to remove SP checks." date="2014-08-07T14:55:00.409-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-08-07T14:56:50.571-04:00">INTERIM</status_change>
            <status_change date="2014-08-25T04:00:24.412-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5341" test_ref="oval:org.mitre.oval:tst:114964"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21389" test_ref="oval:org.mitre.oval:tst:114956"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista/2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19098" test_ref="oval:org.mitre.oval:tst:114438"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23389" test_ref="oval:org.mitre.oval:tst:114853"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23598" test_ref="oval:org.mitre.oval:tst:114669"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19539" test_ref="oval:org.mitre.oval:tst:114916"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23598" test_ref="oval:org.mitre.oval:tst:114669"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18472" test_ref="oval:org.mitre.oval:tst:114770"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22686" test_ref="oval:org.mitre.oval:tst:114915"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16555" test_ref="oval:org.mitre.oval:tst:114960"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20666" test_ref="oval:org.mitre.oval:tst:114734"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16921" test_ref="oval:org.mitre.oval:tst:114739"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21044" test_ref="oval:org.mitre.oval:tst:114922"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16668" test_ref="oval:org.mitre.oval:tst:114145"/>
                <criteria operator="AND" comment="kb2957689 and kb2929437">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 11.0.9600.17041" test_ref="oval:org.mitre.oval:tst:113778"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17126" test_ref="oval:org.mitre.oval:tst:113991"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 8.1 / 2k12 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16668" test_ref="oval:org.mitre.oval:tst:114145"/>
                <criteria operator="AND" comment="kb2957689 and kb2919355">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 11.0.9600.17037" test_ref="oval:org.mitre.oval:tst:114108"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17126" test_ref="oval:org.mitre.oval:tst:113991"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24120" version="5" class="vulnerability">
      <metadata>
        <title>Vulnerability in the VirtualBox component in Oracle VirtualBox 4.2.x through 4.2.20 and 4.3.x before 4.3.8 when using 3D Acceleration, allow local guest OS users to execute arbitrary code on the Chromium server (CVE-2014-0981)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>VirtualBox</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-0981" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0981"/>
        <description>VBox/GuestHost/OpenGL/util/net.c in Oracle VirtualBox before 3.2.22, 4.0.x before 4.0.24, 4.1.x before 4.1.32, 4.2.x before 4.2.24, and 4.3.x before 4.3.8, when using 3D Acceleration allows local guest OS users to execute arbitrary code on the Chromium server via crafted Chromium network pointer in a (1) CR_MESSAGE_READBACK or (2) CR_MESSAGE_WRITEBACK message to the VBoxSharedCrOpenGL service, which triggers an arbitrary pointer dereference and memory corruption.  NOTE: this issue was MERGED with CVE-2014-0982 because it is the same type of vulnerability affecting the same set of versions. All CVE users should reference CVE-2014-0981 instead of CVE-2014-0982.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-04-03T08:31:03">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </submitted>
            <status_change date="2014-04-04T10:24:42.126-04:00">DRAFT</status_change>
            <status_change date="2014-04-21T04:00:37.090-04:00">INTERIM</status_change>
            <status_change date="2014-05-12T04:00:33.128-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="VirtualBox is installed" definition_ref="oval:org.mitre.oval:def:11581"/>
        <criterion comment="Check if Oracle VM VirtualBox is installed" test_ref="oval:org.mitre.oval:tst:42006"/>
        <criteria operator="OR" comment="Check versions of VirtualBox">
          <criteria operator="AND" comment="Affected versions of VirtualBox">
            <criterion comment="Check if Oracle VM VirtualBox version is greater than or equals to 4.2.0" test_ref="oval:org.mitre.oval:tst:99857"/>
            <criterion comment="Check if Oracle VM VirtualBox version is less than  or equals to 4.2.20" test_ref="oval:org.mitre.oval:tst:113418"/>
          </criteria>
          <criteria operator="AND" comment="Affected versions of VirtualBox">
            <criterion comment="Check if Oracle VM VirtualBox version is greater than or equals to 4.3.0" test_ref="oval:org.mitre.oval:tst:100120"/>
            <criterion comment="Check if Oracle VM VirtualBox version is less than  or equals to 4.3.6" test_ref="oval:org.mitre.oval:tst:113364"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24093" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability (CVE-2014-1799) - MS14-035</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-1799" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1799"/>
        <description>Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-0282, CVE-2014-1775, CVE-2014-1779, CVE-2014-1803, and CVE-2014-2757.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-06-16T09:23:20">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-06-20T11:21:36.174-04:00">DRAFT</status_change>
            <status_change date="2014-07-07T04:01:02.181-04:00">INTERIM</status_change>
            <status_change date="2014-07-28T04:00:13.167-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24093 - Updated to remove SP checks." date="2014-08-07T14:55:00.409-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-08-07T14:56:53.291-04:00">INTERIM</status_change>
            <status_change date="2014-08-25T04:00:22.804-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="2k3 (x86 + x64 + ia64)">
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5341" test_ref="oval:org.mitre.oval:tst:114964"/>
        </criteria>
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21389" test_ref="oval:org.mitre.oval:tst:114956"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista/2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19098" test_ref="oval:org.mitre.oval:tst:114438"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23389" test_ref="oval:org.mitre.oval:tst:114853"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23598" test_ref="oval:org.mitre.oval:tst:114669"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19539" test_ref="oval:org.mitre.oval:tst:114916"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23598" test_ref="oval:org.mitre.oval:tst:114669"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18472" test_ref="oval:org.mitre.oval:tst:114770"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22686" test_ref="oval:org.mitre.oval:tst:114915"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16555" test_ref="oval:org.mitre.oval:tst:114960"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20666" test_ref="oval:org.mitre.oval:tst:114734"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16921" test_ref="oval:org.mitre.oval:tst:114739"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21044" test_ref="oval:org.mitre.oval:tst:114922"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16668" test_ref="oval:org.mitre.oval:tst:114145"/>
                <criteria operator="AND" comment="kb2957689 and kb2929437">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 11.0.9600.17041" test_ref="oval:org.mitre.oval:tst:113778"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17126" test_ref="oval:org.mitre.oval:tst:113991"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 8.1 / 2k12 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16668" test_ref="oval:org.mitre.oval:tst:114145"/>
                <criteria operator="AND" comment="kb2957689 and kb2919355">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 11.0.9600.17037" test_ref="oval:org.mitre.oval:tst:114108"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17126" test_ref="oval:org.mitre.oval:tst:113991"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24027" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability (CVE-2014-2769) - MS14-035</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-2769" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2769"/>
        <description>Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-1772, CVE-2014-1780, CVE-2014-1794, CVE-2014-1797, CVE-2014-1802, CVE-2014-2756, CVE-2014-2763, CVE-2014-2764, and CVE-2014-2771.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-06-16T09:23:20">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-06-20T11:22:48.022-04:00">DRAFT</status_change>
            <status_change date="2014-07-07T04:01:01.192-04:00">INTERIM</status_change>
            <status_change date="2014-07-28T04:00:12.065-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24027 - Updated to remove SP checks." date="2014-08-07T14:55:00.409-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-08-07T14:56:52.408-04:00">INTERIM</status_change>
            <status_change date="2014-08-25T04:00:22.275-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16921" test_ref="oval:org.mitre.oval:tst:114739"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21044" test_ref="oval:org.mitre.oval:tst:114922"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16668" test_ref="oval:org.mitre.oval:tst:114145"/>
                <criteria operator="AND" comment="kb2957689 and kb2929437">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 11.0.9600.17041" test_ref="oval:org.mitre.oval:tst:113778"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17126" test_ref="oval:org.mitre.oval:tst:113991"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 8.1 / 2k12 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16668" test_ref="oval:org.mitre.oval:tst:114145"/>
                <criteria operator="AND" comment="kb2957689 and kb2919355">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 11.0.9600.17037" test_ref="oval:org.mitre.oval:tst:114108"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17126" test_ref="oval:org.mitre.oval:tst:113991"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24026" version="3" class="vulnerability">
      <metadata>
        <title>Vulnerability in the VirtualBox component in Oracle VirtualBox 4.2.x through 4.2.20 and 4.3.x before 4.3.8 when using 3D Acceleration, allow local guest OS users to execute arbitrary code on the Chromium server (CVE-2014-0983)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>VirtualBox</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-0983" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0983"/>
        <description>Multiple array index errors in programs that are automatically generated by VBox/HostServices/SharedOpenGL/crserverlib/server_dispatch.py in Oracle VirtualBox 4.2.x through 4.2.20 and 4.3.x before 4.3.8, when using 3D Acceleration, allow local guest OS users to execute arbitrary code on the Chromium server via certain CR_MESSAGE_OPCODES messages with a crafted index, which are not properly handled by the (1) CR_VERTEXATTRIB4NUBARB_OPCODE to the crServerDispatchVertexAttrib4NubARB function, (2) CR_VERTEXATTRIB1DARB_OPCODE to the crServerDispatchVertexAttrib1dARB function, (3) CR_VERTEXATTRIB1FARB_OPCODE to the crServerDispatchVertexAttrib1fARB function, (4) CR_VERTEXATTRIB1SARB_OPCODE to the crServerDispatchVertexAttrib1sARB function, (5) CR_VERTEXATTRIB2DARB_OPCODE to the crServerDispatchVertexAttrib2dARB function, (6) CR_VERTEXATTRIB2FARB_OPCODE to the crServerDispatchVertexAttrib2fARB function, (7) CR_VERTEXATTRIB2SARB_OPCODE to the crServerDispatchVertexAttrib2sARB function, (8) CR_VERTEXATTRIB3DARB_OPCODE to the crServerDispatchVertexAttrib3dARB function, (9) CR_VERTEXATTRIB3FARB_OPCODE to the crServerDispatchVertexAttrib3fARB function, (10) CR_VERTEXATTRIB3SARB_OPCODE to the crServerDispatchVertexAttrib3sARB function, (11) CR_VERTEXATTRIB4DARB_OPCODE to the crServerDispatchVertexAttrib4dARB function, (12) CR_VERTEXATTRIB4FARB_OPCODE to the crServerDispatchVertexAttrib4fARB function, and (13) CR_VERTEXATTRIB4SARB_OPCODE to the crServerDispatchVertexAttrib4sARB function.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-04-03T08:31:03">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </submitted>
            <status_change date="2014-04-04T10:24:41.750-04:00">DRAFT</status_change>
            <status_change date="2014-04-21T04:00:34.902-04:00">INTERIM</status_change>
            <status_change date="2014-05-12T04:00:30.503-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="VirtualBox is installed" definition_ref="oval:org.mitre.oval:def:11581"/>
        <criterion comment="Check if Oracle VM VirtualBox is installed" test_ref="oval:org.mitre.oval:tst:42006"/>
        <criteria operator="OR" comment="Check versions of VirtualBox">
          <criteria operator="AND" comment="Affected versions of VirtualBox">
            <criterion comment="Check if Oracle VM VirtualBox version is greater than or equals to 4.2.0" test_ref="oval:org.mitre.oval:tst:99857"/>
            <criterion comment="Check if Oracle VM VirtualBox version is less than  or equals to 4.2.20" test_ref="oval:org.mitre.oval:tst:113418"/>
          </criteria>
          <criteria operator="AND" comment="Affected versions of VirtualBox">
            <criterion comment="Check if Oracle VM VirtualBox version is greater than or equals to 4.3.0" test_ref="oval:org.mitre.oval:tst:100120"/>
            <criterion comment="Check if Oracle VM VirtualBox version is less than  or equals to 4.3.6" test_ref="oval:org.mitre.oval:tst:113364"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24023" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability (CVE-2014-1795) - MS14-035</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-1795" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1795"/>
        <description>Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-1773, CVE-2014-1783, CVE-2014-1784, CVE-2014-1786, CVE-2014-1805, CVE-2014-2758, CVE-2014-2759, CVE-2014-2765, CVE-2014-2766, and CVE-2014-2775.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-06-16T09:23:20">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-06-20T11:22:04.244-04:00">DRAFT</status_change>
            <status_change date="2014-07-07T04:01:00.926-04:00">INTERIM</status_change>
            <status_change date="2014-07-28T04:00:11.663-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24023 - Updated to remove SP checks." date="2014-08-07T14:56:00.647-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-08-07T14:58:16.949-04:00">INTERIM</status_change>
            <status_change date="2014-08-25T04:00:21.671-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16555" test_ref="oval:org.mitre.oval:tst:114960"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20666" test_ref="oval:org.mitre.oval:tst:114734"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16921" test_ref="oval:org.mitre.oval:tst:114739"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21044" test_ref="oval:org.mitre.oval:tst:114922"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16668" test_ref="oval:org.mitre.oval:tst:114145"/>
                <criteria operator="AND" comment="kb2957689 and kb2929437">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 11.0.9600.17041" test_ref="oval:org.mitre.oval:tst:113778"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17126" test_ref="oval:org.mitre.oval:tst:113991"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 8.1 / 2k12 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16668" test_ref="oval:org.mitre.oval:tst:114145"/>
                <criteria operator="AND" comment="kb2957689 and kb2919355">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 11.0.9600.17037" test_ref="oval:org.mitre.oval:tst:114108"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17126" test_ref="oval:org.mitre.oval:tst:113991"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24022" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer Elevation of Privilege Vulnerability (CVE-2014-1791) - MS14-035</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-1791" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1791"/>
        <description>Microsoft Internet Explorer 7 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-06-16T09:23:20">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-06-20T11:22:45.359-04:00">DRAFT</status_change>
            <status_change date="2014-07-07T04:01:00.540-04:00">INTERIM</status_change>
            <status_change date="2014-07-28T04:00:10.226-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24022 - Updated to remove SP checks." date="2014-08-07T14:55:00.409-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-08-07T14:56:56.247-04:00">INTERIM</status_change>
            <status_change date="2014-08-25T04:00:19.761-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 7 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 for Itanium is installed" definition_ref="oval:org.mitre.oval:def:1867"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21389" test_ref="oval:org.mitre.oval:tst:114956"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista/2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19098" test_ref="oval:org.mitre.oval:tst:114438"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23389" test_ref="oval:org.mitre.oval:tst:114853"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vulnerable os and their respective file versions">
            <criteria operator="AND" comment="2k3(x86 + x64+ ia64) + vulnerable file versions">
              <criteria operator="OR" comment="2k3(x86 + x64 + ia64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23598" test_ref="oval:org.mitre.oval:tst:114669"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2k8 + vulnerable file versions">
              <criteria operator="OR" comment="Vista/ 2k8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19539" test_ref="oval:org.mitre.oval:tst:114916"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23598" test_ref="oval:org.mitre.oval:tst:114669"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18472" test_ref="oval:org.mitre.oval:tst:114770"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22686" test_ref="oval:org.mitre.oval:tst:114915"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="vista/2k8/win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16555" test_ref="oval:org.mitre.oval:tst:114960"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20666" test_ref="oval:org.mitre.oval:tst:114734"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7/R2 Win 8/ 2k12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16921" test_ref="oval:org.mitre.oval:tst:114739"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.21000" test_ref="oval:org.mitre.oval:tst:114527"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.21044" test_ref="oval:org.mitre.oval:tst:114922"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 + vulnerable os and file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7/ 2k8 R2/ 8.1/2k12 R2 and vulnerable file version">
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / 2k8 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16668" test_ref="oval:org.mitre.oval:tst:114145"/>
                <criteria operator="AND" comment="kb2957689 and kb2929437">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 11.0.9600.17041" test_ref="oval:org.mitre.oval:tst:113778"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17126" test_ref="oval:org.mitre.oval:tst:113991"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 8.1 / 2k12 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
                <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
                <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
                <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16668" test_ref="oval:org.mitre.oval:tst:114145"/>
                <criteria operator="AND" comment="kb2957689 and kb2919355">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 11.0.9600.17037" test_ref="oval:org.mitre.oval:tst:114108"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.17126" test_ref="oval:org.mitre.oval:tst:113991"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1867" version="10" class="inventory">
      <metadata>
        <title>Microsoft Windows Server 2003 for Itanium is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/o:microsoft:windows_server_2003:::itanium"/>
        <description>A version of Microsoft Windows Server 2003 for Itanium is
          installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-04-10T16:31:02">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </submitted>
            <status_change date="2007-04-25T19:52:20.536-04:00">INTERIM</status_change>
            <status_change date="2007-05-23T15:05:33.881-04:00">ACCEPTED</status_change>
            <modified comment="Changed the CPE reference" date="2008-04-04T11:17:00.945-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2008-04-04T11:24:23.967-04:00">INTERIM</status_change>
            <status_change date="2008-04-21T04:00:14.656-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:1867 - Updated Windows 2003 Server CPE names." date="2011-03-29T13:48:00.699-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-03-29T13:51:33.404-04:00">INTERIM</status_change>
            <status_change date="2011-04-18T04:00:34.881-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:1867 - Modifications vary from minor OVAL title/description changes to suggesting an alternative CPE name to use." date="2011-09-28T11:29:00.976-04:00">
              <contributor organization="The MITRE Corporation">David Rothenberg</contributor>
            </modified>
            <status_change date="2011-09-28T11:33:43.469-04:00">INTERIM</status_change>
            <status_change date="2011-10-17T04:00:13.370-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:1867 - Un-deprecated incorrect partially deprecation of two Definitions." date="2011-12-09T17:21:00.310-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2011-12-09T17:23:42.622-05:00">INTERIM</status_change>
            <status_change date="2011-12-26T04:02:48.929-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:1867 - Multiple updates to several Windows OVAL entities. Includes CPE, title, and description updates. Fixed incorrectly referenced criteria. Added new criteria, fixed criteria checks, and improved criteria comments for several definitions." date="2012-11-02T20:20:00.882-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2012-11-02T20:24:45.532-04:00">INTERIM</status_change>
            <status_change date="2012-11-19T04:00:33.002-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Microsoft Windows Server 2003 is installed" definition_ref="oval:org.mitre.oval:def:128"/>
        <criterion comment="a version of Windows for the ia64 architecture is installed" test_ref="oval:org.mitre.oval:tst:2747"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:128" version="7" class="inventory">
      <metadata>
        <title>Microsoft Windows Server 2003 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/o:microsoft:windows_2003_server"/>
        <description>The operating system installed on the system is Microsoft Windows Server
          2003.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-06-26T12:55:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <status_change date="2006-06-26T12:55:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Added CPE reference." date="2007-04-30T07:48:00.775-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-04-30T08:05:37.807-04:00">INTERIM</status_change>
            <status_change date="2007-05-23T15:05:26.547-04:00">ACCEPTED</status_change>
            <modified comment="Changed the CPE reference" date="2008-04-04T11:17:00.348-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2008-04-04T11:26:22.372-04:00">INTERIM</status_change>
            <status_change date="2008-04-21T04:00:11.254-04:00">ACCEPTED</status_change>
            <modified comment="Changed the test for windows to be case insensitive and replaced the test for Windows 5.2 with a new test for 2003" date="2009-12-02T16:05:00.749-04:00">
              <contributor organization="National Institute of Standards and Technology">Tim
                Harrison</contributor>
            </modified>
            <status_change date="2009-12-02T16:05:00.749-04:00">INTERIM</status_change>
            <modified comment="Added anchors and spaces to regular expression" date="2009-12-04T14:56:00.085-05:00">
              <contributor organization="National Institute of Standards and Technology">Tim
                Harrison</contributor>
            </modified>
            <modified comment="Updating regex to include parenthesis" date="2009-12-08T17:31:00.354-05:00">
              <contributor organization="National Institute of Standards and Technology">Tim
                Harrison</contributor>
            </modified>
            <status_change date="2009-12-28T04:00:06.591-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:128 - Updated CPE reference" date="2011-02-17T13:33:00.123-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2011-02-17T13:35:10.049-05:00">INTERIM</status_change>
            <status_change date="2011-03-07T04:00:10.940-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="the installed operating system is part of the Microsoft Windows family" test_ref="oval:org.mitre.oval:tst:99"/>
        <criterion comment="Windows Server 2003 is installed" test_ref="oval:org.mitre.oval:tst:11145"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22660" version="6" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability (CVE-2014-0322) - MS14-012</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-0322" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0322"/>
        <description>Use-after-free vulnerability in Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code via vectors involving crafted JavaScript code, CMarkup, and the onpropertychange attribute of a script element, as exploited in the wild in January and February 2014.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-03-13T06:57:21">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-03-14T10:58:44.741-04:00">DRAFT</status_change>
            <status_change date="2014-03-31T04:00:37.266-04:00">INTERIM</status_change>
            <status_change date="2014-04-21T04:00:30.113-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:22660 - extended definitions of OS are without SP checks" date="2014-07-28T18:08:00.084-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T18:10:09.043-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:02:26.341-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 9 and vulnerable file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="Win 7 / R2 / Vista / 2K8">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16540" test_ref="oval:org.mitre.oval:tst:100887"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20651" test_ref="oval:org.mitre.oval:tst:100703"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 and vulnerable file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7 / R2/ Win 8 / 2K12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16843" test_ref="oval:org.mitre.oval:tst:100896"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.20000" test_ref="oval:org.mitre.oval:tst:80523"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.20963" test_ref="oval:org.mitre.oval:tst:100791"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22652" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability (CVE-2014-0297) - MS14-012</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-0297" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0297"/>
        <description>Microsoft Internet Explorer 8 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-0308, CVE-2014-0312, and CVE-2014-0324.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-03-13T06:57:21">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-03-14T10:58:36.344-04:00">DRAFT</status_change>
            <status_change date="2014-03-31T04:00:37.053-04:00">INTERIM</status_change>
            <status_change date="2014-04-21T04:00:29.843-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:22652 - extended definitions of OS are without SP checks" date="2014-07-28T18:06:00.495-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T18:08:38.900-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:02:26.023-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 8 and vulnerable file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="Check for vulnerable OS and files">
            <criteria operator="AND" comment="XP / 2k3 and vulnerable file version">
              <criteria operator="OR" comment="XP / 2K3">
                <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
                <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23569" test_ref="oval:org.mitre.oval:tst:100829"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista / 2K8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19507" test_ref="oval:org.mitre.oval:tst:100836"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23569" test_ref="oval:org.mitre.oval:tst:100829"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vulnerable file version">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18392" test_ref="oval:org.mitre.oval:tst:100526"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22597" test_ref="oval:org.mitre.oval:tst:100560"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 and vulnerable file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="Win 7 / R2 / Vista / 2K8">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16540" test_ref="oval:org.mitre.oval:tst:100887"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20651" test_ref="oval:org.mitre.oval:tst:100703"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 and vulnerable file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7 / R2/ Win 8 / 2K12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16843" test_ref="oval:org.mitre.oval:tst:100896"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.20000" test_ref="oval:org.mitre.oval:tst:80523"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.20963" test_ref="oval:org.mitre.oval:tst:100791"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 and vulnerable file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7 / R2/ Win 8.1 / 2K12 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16521" test_ref="oval:org.mitre.oval:tst:100855"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22633" version="3" class="vulnerability">
      <metadata>
        <title>Win32k Information Disclosure Vulnerability - CVE-2014-0323 (MS14-015)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-0323" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0323"/>
        <description>win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to obtain sensitive information from kernel memory or cause a denial of service (system hang) via a crafted application, aka "Win32k Information Disclosure Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-03-13T14:34:18">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-03-14T11:06:05.764-04:00">DRAFT</status_change>
            <status_change date="2014-03-31T04:00:36.877-04:00">INTERIM</status_change>
            <status_change date="2014-04-21T04:00:29.564-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="XP (x86)+ vulnerable file version">
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <criterion comment="Check if the version of win32k.sys is less than 5.1.2600.6514" test_ref="oval:org.mitre.oval:tst:100494"/>
        </criteria>
        <criteria operator="AND" comment="XP X64/2K3(all) and vulnerable file version">
          <criteria operator="OR" comment="XP x64 / 2k3">
            <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
          </criteria>
          <criterion comment="Check if the version of win32k.sys is less than 5.2.3790.5296" test_ref="oval:org.mitre.oval:tst:100886"/>
        </criteria>
        <criteria operator="AND" comment="Vista / 2k8 + vulnerable file version">
          <criteria operator="OR" comment="Vista / 2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
            <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of win32k.sys is less than 6.0.6002.19036" test_ref="oval:org.mitre.oval:tst:100733"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:81723"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.0.6002.23325" test_ref="oval:org.mitre.oval:tst:100089"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / R2 + vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12292"/>
            <extend_definition comment="Microsoft Windows 7 x64 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12627"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12567"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12583"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.18388" test_ref="oval:org.mitre.oval:tst:100894"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:81763"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.22592" test_ref="oval:org.mitre.oval:tst:100902"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8/2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.16817" test_ref="oval:org.mitre.oval:tst:100579"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.2.9200.20000" test_ref="oval:org.mitre.oval:tst:80697"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.20937" test_ref="oval:org.mitre.oval:tst:100323"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1 / 2K12 R2and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of win32k.sys is less than 6.3.9600.16650" test_ref="oval:org.mitre.oval:tst:100702"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22610" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability (CVE-2014-0312) - MS14-012</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-0312" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0312"/>
        <description>Microsoft Internet Explorer 8 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-0297, CVE-2014-0308, and CVE-2014-0324.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-03-13T06:57:21">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-03-14T10:58:55.818-04:00">DRAFT</status_change>
            <status_change date="2014-03-31T04:00:36.501-04:00">INTERIM</status_change>
            <status_change date="2014-04-21T04:00:29.005-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:22610 - extended definitions of OS are without SP checks" date="2014-07-28T18:06:00.495-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T18:08:39.755-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:02:25.752-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 8 and vulnerable file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="Check for vulnerable OS and files">
            <criteria operator="AND" comment="XP / 2k3 and vulnerable file version">
              <criteria operator="OR" comment="XP / 2K3">
                <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
                <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23569" test_ref="oval:org.mitre.oval:tst:100829"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista / 2K8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19507" test_ref="oval:org.mitre.oval:tst:100836"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23569" test_ref="oval:org.mitre.oval:tst:100829"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vulnerable file version">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18392" test_ref="oval:org.mitre.oval:tst:100526"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22597" test_ref="oval:org.mitre.oval:tst:100560"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 and vulnerable file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="Win 7 / R2 / Vista / 2K8">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16540" test_ref="oval:org.mitre.oval:tst:100887"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20651" test_ref="oval:org.mitre.oval:tst:100703"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 and vulnerable file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7 / R2/ Win 8 / 2K12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16843" test_ref="oval:org.mitre.oval:tst:100896"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.20000" test_ref="oval:org.mitre.oval:tst:80523"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.20963" test_ref="oval:org.mitre.oval:tst:100791"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 and vulnerable file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7 / R2/ Win 8.1 / 2K12 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16521" test_ref="oval:org.mitre.oval:tst:100855"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22607" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability (CVE-2014-0305) - MS14-012</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-0305" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0305"/>
        <description>Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-0299 and CVE-2014-0311.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-03-13T06:57:21">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-03-14T10:59:02.169-04:00">DRAFT</status_change>
            <status_change date="2014-03-31T04:00:36.308-04:00">INTERIM</status_change>
            <status_change date="2014-04-21T04:00:28.709-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:22607 - extended definitions of OS are without SP checks" date="2014-07-28T18:08:00.084-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T18:10:10.316-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:02:25.347-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 and vulnerable file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="Check for vulnerable OS and files">
            <criteria operator="AND" comment="XP 32 bit and vulnerable file version">
              <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
              <criterion comment="Check if the version of mshtml.dll is less than 6.0.2900.6512" test_ref="oval:org.mitre.oval:tst:99906"/>
            </criteria>
            <criteria operator="AND" comment="XP X64 / 2k3 and vulnerable file version">
              <criteria operator="OR" comment="XP x64 / 2k3">
                <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5294" test_ref="oval:org.mitre.oval:tst:100280"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 7 and vulnerable file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="Check for vulnerable OS and files">
            <criteria operator="AND" comment="XP / 2k3 and vulnerable file version">
              <criteria operator="OR" comment="XP / 2K3">
                <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
                <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21371" test_ref="oval:org.mitre.oval:tst:100174"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2K8 and vulnerable file version">
              <criteria operator="OR" comment="Vista / 2K8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19041" test_ref="oval:org.mitre.oval:tst:100257"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23330" test_ref="oval:org.mitre.oval:tst:100536"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 and vulnerable file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="Check for vulnerable OS and files">
            <criteria operator="AND" comment="XP / 2k3 and vulnerable file version">
              <criteria operator="OR" comment="XP / 2K3">
                <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
                <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23569" test_ref="oval:org.mitre.oval:tst:100829"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista / 2K8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19507" test_ref="oval:org.mitre.oval:tst:100836"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23569" test_ref="oval:org.mitre.oval:tst:100829"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vulnerable file version">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18392" test_ref="oval:org.mitre.oval:tst:100526"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22597" test_ref="oval:org.mitre.oval:tst:100560"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 and vulnerable file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="Win 7 / R2 / Vista / 2K8">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16540" test_ref="oval:org.mitre.oval:tst:100887"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20651" test_ref="oval:org.mitre.oval:tst:100703"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 and vulnerable file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7 / R2/ Win 8 / 2K12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16843" test_ref="oval:org.mitre.oval:tst:100896"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.20000" test_ref="oval:org.mitre.oval:tst:80523"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.20963" test_ref="oval:org.mitre.oval:tst:100791"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 and vulnerable file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7 / R2/ Win 8.1 / 2K12 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16521" test_ref="oval:org.mitre.oval:tst:100855"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22604" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability (CVE-2014-0299) - MS14-012</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-0299" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0299"/>
        <description>Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-0305 and CVE-2014-0311.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-03-13T06:57:21">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-03-14T10:58:47.323-04:00">DRAFT</status_change>
            <status_change date="2014-03-31T04:00:36.103-04:00">INTERIM</status_change>
            <status_change date="2014-04-21T04:00:28.330-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:22604 - extended definitions of OS are without SP checks" date="2014-07-28T18:06:00.495-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T18:08:38.193-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:02:25.015-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 and vulnerable file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="Check for vulnerable OS and files">
            <criteria operator="AND" comment="XP 32 bit and vulnerable file version">
              <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
              <criterion comment="Check if the version of mshtml.dll is less than 6.0.2900.6512" test_ref="oval:org.mitre.oval:tst:99906"/>
            </criteria>
            <criteria operator="AND" comment="XP X64 / 2k3 and vulnerable file version">
              <criteria operator="OR" comment="XP x64 / 2k3">
                <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5294" test_ref="oval:org.mitre.oval:tst:100280"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 7 and vulnerable file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="Check for vulnerable OS and files">
            <criteria operator="AND" comment="XP / 2k3 and vulnerable file version">
              <criteria operator="OR" comment="XP / 2K3">
                <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
                <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21371" test_ref="oval:org.mitre.oval:tst:100174"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2K8 and vulnerable file version">
              <criteria operator="OR" comment="Vista / 2K8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19041" test_ref="oval:org.mitre.oval:tst:100257"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23330" test_ref="oval:org.mitre.oval:tst:100536"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 and vulnerable file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="Check for vulnerable OS and files">
            <criteria operator="AND" comment="XP / 2k3 and vulnerable file version">
              <criteria operator="OR" comment="XP / 2K3">
                <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
                <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23569" test_ref="oval:org.mitre.oval:tst:100829"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista / 2K8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19507" test_ref="oval:org.mitre.oval:tst:100836"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23569" test_ref="oval:org.mitre.oval:tst:100829"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vulnerable file version">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18392" test_ref="oval:org.mitre.oval:tst:100526"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22597" test_ref="oval:org.mitre.oval:tst:100560"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 and vulnerable file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="Win 7 / R2 / Vista / 2K8">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16540" test_ref="oval:org.mitre.oval:tst:100887"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20651" test_ref="oval:org.mitre.oval:tst:100703"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 and vulnerable file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7 / R2/ Win 8 / 2K12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16843" test_ref="oval:org.mitre.oval:tst:100896"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.20000" test_ref="oval:org.mitre.oval:tst:80523"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.20963" test_ref="oval:org.mitre.oval:tst:100791"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 and vulnerable file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7 / R2/ Win 8.1 / 2K12 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16521" test_ref="oval:org.mitre.oval:tst:100855"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22559" version="5" class="vulnerability">
      <metadata>
        <title>Memory corruption vulnerability in Microsoft Internet Explorer (CVE-2014-0285) - MS14-010</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-0285" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0285"/>
        <description>Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-0275 and CVE-2014-0286.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-02-17T12:48:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-02-19T08:13:12.246-05:00">DRAFT</status_change>
            <status_change date="2014-03-10T04:00:48.643-04:00">INTERIM</status_change>
            <status_change date="2014-03-31T04:00:33.812-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:22559 - extended definitions of OS are without SP checks" date="2014-07-28T18:04:00.247-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T18:06:28.817-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:02:24.009-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="ie6">
          <criteria operator="OR" comment="xp/2003">
            <criteria operator="AND" comment="ie6/xp/version">
              <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
              <criterion comment="Check if the version of mshtml.dll is less than 6.0.2900.6498" test_ref="oval:org.mitre.oval:tst:100192"/>
            </criteria>
            <criteria operator="AND" comment="ie6/xp/2003/versions">
              <criteria operator="OR" comment="xp/2003">
                <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
                <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5281" test_ref="oval:org.mitre.oval:tst:100478"/>
            </criteria>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
        </criteria>
        <criteria operator="AND" comment="ie7">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="xp/2003/vista/2008/">
            <criteria operator="AND" comment="xp/2003/version">
              <criteria operator="OR" comment="either os">
                <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
                <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
                <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21366" test_ref="oval:org.mitre.oval:tst:100587"/>
            </criteria>
            <criteria operator="AND" comment="vista/2008/version">
              <criteria operator="OR" comment="either os">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="gdr/ldr">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19016" test_ref="oval:org.mitre.oval:tst:100315"/>
                <criteria operator="AND" comment="ldr range">
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23303" test_ref="oval:org.mitre.oval:tst:100212"/>
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="ie8">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vista/2008/win7/2008r2//versions">
            <criteria operator="AND" comment="vista/2008/versions">
              <criteria operator="OR" comment="either os">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="gdr/ldr">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19499" test_ref="oval:org.mitre.oval:tst:100606"/>
                <criteria operator="AND" comment="ldr range">
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23562" test_ref="oval:org.mitre.oval:tst:100657"/>
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="win7/2008 r2/version">
              <criteria operator="OR" comment="either os">
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="gdr/ldr">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18365" test_ref="oval:org.mitre.oval:tst:100432"/>
                <criteria operator="AND" comment="ldr range">
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22567" test_ref="oval:org.mitre.oval:tst:100439"/>
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="xp/2003/version">
              <criteria operator="OR" comment="either os">
                <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
                <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23562" test_ref="oval:org.mitre.oval:tst:100657"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="ie9">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16533" test_ref="oval:org.mitre.oval:tst:100604"/>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20644" test_ref="oval:org.mitre.oval:tst:100436"/>
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
            </criteria>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
        </criteria>
        <criteria operator="AND" comment="ie10">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16798" test_ref="oval:org.mitre.oval:tst:100469"/>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.20916" test_ref="oval:org.mitre.oval:tst:100274"/>
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.20000" test_ref="oval:org.mitre.oval:tst:80523"/>
            </criteria>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
        </criteria>
        <criteria operator="AND" comment="ie11">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16518" test_ref="oval:org.mitre.oval:tst:100481"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22512" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability (CVE-2014-0298) - MS14-012</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-0298" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0298"/>
        <description>Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-03-13T06:57:21">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-03-14T10:58:53.469-04:00">DRAFT</status_change>
            <status_change date="2014-03-31T04:00:29.751-04:00">INTERIM</status_change>
            <status_change date="2014-04-21T04:00:26.296-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:22512 - extended definitions of OS are without SP checks" date="2014-07-28T18:06:00.495-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T18:08:39.129-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:02:23.118-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 9 and vulnerable file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="Win 7 / R2 / Vista / 2K8">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16540" test_ref="oval:org.mitre.oval:tst:100887"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20651" test_ref="oval:org.mitre.oval:tst:100703"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 and vulnerable file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7 / R2/ Win 8 / 2K12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16843" test_ref="oval:org.mitre.oval:tst:100896"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.20000" test_ref="oval:org.mitre.oval:tst:80523"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.20963" test_ref="oval:org.mitre.oval:tst:100791"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 and vulnerable file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7 / R2/ Win 8.1 / 2K12 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16521" test_ref="oval:org.mitre.oval:tst:100855"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22510" version="5" class="vulnerability">
      <metadata>
        <title>Memory corruption vulnerability in Microsoft Internet Explorer (CVE-2014-0286) - MS14-010</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-0286" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0286"/>
        <description>Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-0275 and CVE-2014-0285.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-02-17T12:48:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-02-19T08:12:53.512-05:00">DRAFT</status_change>
            <status_change date="2014-03-10T04:00:46.845-04:00">INTERIM</status_change>
            <status_change date="2014-03-31T04:00:29.486-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:22510 - extended definitions of OS are without SP checks" date="2014-07-28T18:04:00.247-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T18:06:30.876-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:02:22.710-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="ie6">
          <criteria operator="OR" comment="xp/2003">
            <criteria operator="AND" comment="ie6/xp/version">
              <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
              <criterion comment="Check if the version of mshtml.dll is less than 6.0.2900.6498" test_ref="oval:org.mitre.oval:tst:100192"/>
            </criteria>
            <criteria operator="AND" comment="ie6/xp/2003/versions">
              <criteria operator="OR" comment="xp/2003">
                <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
                <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5281" test_ref="oval:org.mitre.oval:tst:100478"/>
            </criteria>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
        </criteria>
        <criteria operator="AND" comment="ie7">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="xp/2003/vista/2008/">
            <criteria operator="AND" comment="xp/2003/version">
              <criteria operator="OR" comment="either os">
                <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
                <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
                <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21366" test_ref="oval:org.mitre.oval:tst:100587"/>
            </criteria>
            <criteria operator="AND" comment="vista/2008/version">
              <criteria operator="OR" comment="either os">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="gdr/ldr">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19016" test_ref="oval:org.mitre.oval:tst:100315"/>
                <criteria operator="AND" comment="ldr range">
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23303" test_ref="oval:org.mitre.oval:tst:100212"/>
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="ie8">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vista/2008/win7/2008r2//versions">
            <criteria operator="AND" comment="vista/2008/versions">
              <criteria operator="OR" comment="either os">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="gdr/ldr">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19499" test_ref="oval:org.mitre.oval:tst:100606"/>
                <criteria operator="AND" comment="ldr range">
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23562" test_ref="oval:org.mitre.oval:tst:100657"/>
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="win7/2008 r2/version">
              <criteria operator="OR" comment="either os">
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="gdr/ldr">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18365" test_ref="oval:org.mitre.oval:tst:100432"/>
                <criteria operator="AND" comment="ldr range">
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22567" test_ref="oval:org.mitre.oval:tst:100439"/>
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="xp/2003/version">
              <criteria operator="OR" comment="either os">
                <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
                <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23562" test_ref="oval:org.mitre.oval:tst:100657"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="ie9">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16533" test_ref="oval:org.mitre.oval:tst:100604"/>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20644" test_ref="oval:org.mitre.oval:tst:100436"/>
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
            </criteria>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
        </criteria>
        <criteria operator="AND" comment="ie10">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16798" test_ref="oval:org.mitre.oval:tst:100469"/>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.20916" test_ref="oval:org.mitre.oval:tst:100274"/>
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.20000" test_ref="oval:org.mitre.oval:tst:80523"/>
            </criteria>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
        </criteria>
        <criteria operator="AND" comment="ie11">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16518" test_ref="oval:org.mitre.oval:tst:100481"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22509" version="5" class="vulnerability">
      <metadata>
        <title>Memory corruption vulnerability in Microsoft Internet Explorer (CVE-2014-0284) - MS14-010</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-0284" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0284"/>
        <description>Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-02-17T12:48:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-02-19T08:13:03.062-05:00">DRAFT</status_change>
            <status_change date="2014-03-10T04:00:46.715-04:00">INTERIM</status_change>
            <status_change date="2014-03-31T04:00:29.285-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:22509 - extended definitions of OS are without SP checks" date="2014-07-28T18:04:00.247-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T18:06:29.817-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:02:22.500-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="ie9">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16533" test_ref="oval:org.mitre.oval:tst:100604"/>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20644" test_ref="oval:org.mitre.oval:tst:100436"/>
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
            </criteria>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
        </criteria>
        <criteria operator="AND" comment="ie10">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16798" test_ref="oval:org.mitre.oval:tst:100469"/>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.20916" test_ref="oval:org.mitre.oval:tst:100274"/>
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.20000" test_ref="oval:org.mitre.oval:tst:80523"/>
            </criteria>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22508" version="3" class="vulnerability">
      <metadata>
        <title>DirectShow Memory Corruption Vulnerability - CVE-2014-0301 (MS14-013)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-0301" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0301"/>
        <description>Double free vulnerability in qedit.dll in DirectShow in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 allows remote attackers to execute arbitrary code via a crafted JPEG image, aka "DirectShow Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-03-13T12:04:24">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-03-14T11:01:15.482-04:00">DRAFT</status_change>
            <status_change date="2014-03-31T04:00:29.038-04:00">INTERIM</status_change>
            <status_change date="2014-04-21T04:00:26.053-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Win XP and vulnerable file version">
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <criterion comment="Check if the version of qedit.dll is less than 6.5.2600.6512" test_ref="oval:org.mitre.oval:tst:100735"/>
        </criteria>
        <criteria operator="AND" comment="XP x64 / 2k3(all) and vulnerable file version">
          <criteria operator="OR" comment="XP X64 / 2K3">
            <extend_definition comment="Microsoft Windows XP SP2 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:1799"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
          </criteria>
          <criterion comment="Check if the version of qedit.dll is less than 6.5.3790.5294" test_ref="oval:org.mitre.oval:tst:100416"/>
        </criteria>
        <criteria operator="AND" comment="Vista/2K8 and vulnerable file version">
          <criteria operator="OR" comment="Vista / 2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of qedit.dll is less than 6.6.6002.19033" test_ref="oval:org.mitre.oval:tst:100900"/>
            <criteria operator="AND" comment="Check for LDR range">
              <criterion comment="Check if the version of qedit.dll is greater than or equal to 6.6.6002.23000" test_ref="oval:org.mitre.oval:tst:81807"/>
              <criterion comment="Check if the version of qedit.dll is less than 6.6.6002.23321" test_ref="oval:org.mitre.oval:tst:100852"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / R2 and vulnerable version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12292"/>
            <extend_definition comment="Microsoft Windows 7 x64 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12627"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12567"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of qedit.dll is less than 6.6.7601.18386" test_ref="oval:org.mitre.oval:tst:100823"/>
            <criteria operator="AND" comment="Check for LDR range">
              <criterion comment="Check if the version of qedit.dll is greater than or equal to 6.6.7601.22000" test_ref="oval:org.mitre.oval:tst:81771"/>
              <criterion comment="Check if the version of qedit.dll is less than 6.6.7601.22590" test_ref="oval:org.mitre.oval:tst:100871"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8 / 2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of qedit.dll is less than 6.6.9200.16812" test_ref="oval:org.mitre.oval:tst:100903"/>
            <criteria operator="AND" comment="Check for LDR range">
              <criterion comment="Check if the version of qedit.dll is greater than or equal to 6.6.9200.20000" test_ref="oval:org.mitre.oval:tst:81492"/>
              <criterion comment="Check if the version of qedit.dll is less than 6.6.9200.20931" test_ref="oval:org.mitre.oval:tst:100638"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="8.1/2012 R2 and vulnerable version">
          <criteria operator="OR" comment="8.1/2012 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
          </criteria>
          <criterion comment="Check if the version of qedit.dll is less than 6.6.9600.16650" test_ref="oval:org.mitre.oval:tst:100729"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22500" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability (CVE-2014-0308) - MS14-012</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-0308" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0308"/>
        <description>Microsoft Internet Explorer 8 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-0297, CVE-2014-0312, and CVE-2014-0324.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-03-13T06:57:21">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-03-14T10:58:59.228-04:00">DRAFT</status_change>
            <status_change date="2014-03-31T04:00:28.730-04:00">INTERIM</status_change>
            <status_change date="2014-04-21T04:00:25.719-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:22500 - extended definitions of OS are without SP checks" date="2014-07-28T18:08:00.084-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T18:10:08.759-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:02:22.236-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 8 and vulnerable file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="Check for vulnerable OS and files">
            <criteria operator="AND" comment="XP / 2k3 and vulnerable file version">
              <criteria operator="OR" comment="XP / 2K3">
                <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
                <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23569" test_ref="oval:org.mitre.oval:tst:100829"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista / 2K8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19507" test_ref="oval:org.mitre.oval:tst:100836"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23569" test_ref="oval:org.mitre.oval:tst:100829"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vulnerable file version">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18392" test_ref="oval:org.mitre.oval:tst:100526"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22597" test_ref="oval:org.mitre.oval:tst:100560"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 and vulnerable file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="Win 7 / R2 / Vista / 2K8">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16540" test_ref="oval:org.mitre.oval:tst:100887"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20651" test_ref="oval:org.mitre.oval:tst:100703"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 and vulnerable file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7 / R2/ Win 8 / 2K12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16843" test_ref="oval:org.mitre.oval:tst:100896"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.20000" test_ref="oval:org.mitre.oval:tst:80523"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.20963" test_ref="oval:org.mitre.oval:tst:100791"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 and vulnerable file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7 / R2/ Win 8.1 / 2K12 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16521" test_ref="oval:org.mitre.oval:tst:100855"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22497" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability (CVE-2014-0313) - MS14-012</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-0313" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0313"/>
        <description>Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-0321.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-03-13T06:57:21">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-03-14T10:59:05.170-04:00">DRAFT</status_change>
            <status_change date="2014-03-31T04:00:28.613-04:00">INTERIM</status_change>
            <status_change date="2014-04-21T04:00:25.486-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:22497 - extended definitions of OS are without SP checks" date="2014-07-28T18:08:00.084-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T18:10:08.558-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:02:22.030-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 10 and vulnerable file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7 / R2/ Win 8 / 2K12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16843" test_ref="oval:org.mitre.oval:tst:100896"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.20000" test_ref="oval:org.mitre.oval:tst:80523"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.20963" test_ref="oval:org.mitre.oval:tst:100791"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 and vulnerable file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7 / R2/ Win 8.1 / 2K12 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16521" test_ref="oval:org.mitre.oval:tst:100855"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22481" version="5" class="vulnerability">
      <metadata>
        <title>Memory corruption vulnerability in Microsoft Internet Explorer (CVE-2014-0288) - MS14-010</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-0288" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0288"/>
        <description>Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-0270, CVE-2014-0273, and CVE-2014-0274.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-02-17T12:48:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-02-19T08:13:00.731-05:00">DRAFT</status_change>
            <status_change date="2014-03-10T04:00:46.283-04:00">INTERIM</status_change>
            <status_change date="2014-03-31T04:00:28.147-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:22481 - extended definitions of OS are without SP checks" date="2014-07-28T18:04:00.247-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T18:06:32.038-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:02:21.821-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="ie9">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16533" test_ref="oval:org.mitre.oval:tst:100604"/>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20644" test_ref="oval:org.mitre.oval:tst:100436"/>
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
            </criteria>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
        </criteria>
        <criteria operator="AND" comment="ie10">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16798" test_ref="oval:org.mitre.oval:tst:100469"/>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.20916" test_ref="oval:org.mitre.oval:tst:100274"/>
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.20000" test_ref="oval:org.mitre.oval:tst:80523"/>
            </criteria>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
        </criteria>
        <criteria operator="AND" comment="ie11">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16518" test_ref="oval:org.mitre.oval:tst:100481"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22472" version="5" class="vulnerability">
      <metadata>
        <title>Type Traversal Vulnerability (CVE-2014-0257) - MS14-009</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft .NET Framework 1.1</product>
          <product>Microsoft .NET Framework 2.0</product>
          <product>Microsoft .NET Framework 3.0</product>
          <product>Microsoft .NET Framework 3.5</product>
          <product>Microsoft .NET Framework 3.5.1</product>
          <product>Microsoft .NET Framework 4.0</product>
          <product>Microsoft .NET Framework 4.5</product>
          <product>Microsoft .NET Framework 4.5.1</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-0257" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0257"/>
        <description>Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.5, 3.5.1, 4, 4.5, and 4.5.1 does not properly determine whether it is safe to execute a method, which allows remote attackers to execute arbitrary code via (1) a crafted web site or (2) a crafted .NET Framework application that exposes a COM server endpoint, aka "Type Traversal Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-02-18T02:39:12">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-02-19T08:22:25.792-05:00">DRAFT</status_change>
            <status_change date="2014-03-10T04:00:45.622-04:00">INTERIM</status_change>
            <status_change date="2014-03-31T04:00:27.275-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:22472 - extended definitions of OS are without SP checks" date="2014-07-28T18:04:00.247-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T18:06:32.297-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:02:21.340-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment=".net 2.0 sp2/xp/server 2003/versions">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 2.0 Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6158"/>
          <criteria operator="OR" comment="either file versions GDR/LDR">
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of mscorlib.dll is greater than or equal to 2.0.50727.7000" test_ref="oval:org.mitre.oval:tst:80994"/>
              <criterion comment="Check if the version of mscorlib.dll is less than 2.0.50727.7041" test_ref="oval:org.mitre.oval:tst:100190"/>
            </criteria>
            <criterion comment="Check if the version of mscorlib.dll is less than 2.0.50727.3655" test_ref="oval:org.mitre.oval:tst:99855"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment=".net 2.0 sp2/vista/server 2008/versions">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 2.0 Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6158"/>
          <criteria operator="OR" comment="either file versions">
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of mscorlib.dll is greater than or equal to 2.0.50727.7000" test_ref="oval:org.mitre.oval:tst:80994"/>
              <criterion comment="Check if the version of mscorlib.dll is less than 2.0.50727.7041" test_ref="oval:org.mitre.oval:tst:100190"/>
            </criteria>
            <criterion comment="Check if the version of mscorlib.dll is less than 2.0.50727.4247" test_ref="oval:org.mitre.oval:tst:100462"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment=".net 3.5/win 8/server 2012/versions">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
          </criteria>
          <criteria operator="OR" comment="either file versions">
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of mscorlib.dll is less than 2.0.50727.7041" test_ref="oval:org.mitre.oval:tst:100190"/>
              <criterion comment="Check if the version of mscorlib.dll is greater than or equal to 2.0.50727.7000" test_ref="oval:org.mitre.oval:tst:80994"/>
            </criteria>
            <criterion comment="Check if the version is mscorlib.dll less than 2.0.50727.6413" test_ref="oval:org.mitre.oval:tst:100289"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 3.5 SP1 is installed" definition_ref="oval:org.mitre.oval:def:12542"/>
        </criteria>
        <criteria operator="AND" comment=".net 3.5.1/win 7/server 2008 R2/versions">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 3.5 SP1 is installed" definition_ref="oval:org.mitre.oval:def:12542"/>
          <criteria operator="OR" comment="either file versions">
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of mscorlib.dll is less than 2.0.50727.7041" test_ref="oval:org.mitre.oval:tst:100190"/>
              <criterion comment="Check if the version of mscorlib.dll is greater than or equal to 2.0.50727.7000" test_ref="oval:org.mitre.oval:tst:80994"/>
            </criteria>
            <criterion comment="Check if the version of mscorlib.dll is less than 2.0.50727.5477" test_ref="oval:org.mitre.oval:tst:100730"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment=".net 4.0/win xp.server 2003/vista/server 2008/win 7/server 2008 R2/versions">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6749"/>
          <criteria operator="OR" comment="either file versions">
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of mscorlib.dll is less than 4.0.30319.2034" test_ref="oval:org.mitre.oval:tst:100290"/>
              <criterion comment="Check if the version of mscorlib.dll is greater than or equal to 4.0.30319.2000" test_ref="oval:org.mitre.oval:tst:81701"/>
            </criteria>
            <criterion comment="Check if the version of mscorlib.dll is less than 4.0.30319.1022" test_ref="oval:org.mitre.oval:tst:100576"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment=".net 4.5/vista/server 2008/win 7/server 2008 R2/versions">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 4.5 is installed" definition_ref="oval:org.mitre.oval:def:15925"/>
          <criteria operator="OR" comment="either file versions">
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of mscorlib.dll is less than 4.0.30319.19132" test_ref="oval:org.mitre.oval:tst:100509"/>
              <criterion comment="Check if the version of mscorlib.dll is greater than or equal to 4.0.30319.19000" test_ref="oval:org.mitre.oval:tst:80125"/>
            </criteria>
            <criterion comment="Check if the version of mscorlib.dll is less than 4.0.30319.18063" test_ref="oval:org.mitre.oval:tst:100363"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment=".net 4.5/win 8/server 2012/versions">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 4.5 is installed" definition_ref="oval:org.mitre.oval:def:15925"/>
          <criteria operator="OR" comment="either file versions">
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of mscorlib.dll is less than 4.0.30319.19455" test_ref="oval:org.mitre.oval:tst:100693"/>
              <criterion comment="Check if the version of mscorlib.dll is greater than or equal to 4.0.30319.19000" test_ref="oval:org.mitre.oval:tst:80125"/>
            </criteria>
            <criterion comment="Check if the version of mscorlib.dll is less than 4.0.30319.18449" test_ref="oval:org.mitre.oval:tst:100689"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment=".NET 1.1 and vulnerable file">
          <extend_definition comment="Microsoft .NET Framework 1.1 Service Pack 1 is Installed" definition_ref="oval:org.mitre.oval:def:1834"/>
          <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
          <criterion comment="Check if the version of mscorlib.dll is less than 1.1.4322.2504" test_ref="oval:org.mitre.oval:tst:100537"/>
        </criteria>
        <criteria operator="AND" comment=".NET 4.5.1 and Win Vista / 7 / 2008 / 2008R2">
          <criteria operator="OR" comment="Either OS">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
          </criteria>
          <criterion comment="Check if the version of mscorlib.dll is less than 4.0.30319.18444" test_ref="oval:org.mitre.oval:tst:100309"/>
          <extend_definition comment="Microsoft .NET Framework 4.5.1 is installed" definition_ref="oval:org.mitre.oval:def:22275"/>
        </criteria>
        <criteria operator="AND" comment=".NET 4.5.1 and Win 8 / Server 2012">
          <criteria operator="OR" comment="Either OS">
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="gdr and ldr range">
            <criteria operator="AND" comment="ldr range for system.web.dll">
              <criterion comment="Check if the version of mscorlib.dll is less than 4.0.30319.19455" test_ref="oval:org.mitre.oval:tst:100693"/>
              <criterion comment="Check if the version of mscorlib.dll is greater than or equal to 4.0.30319.19000" test_ref="oval:org.mitre.oval:tst:80125"/>
            </criteria>
            <criterion comment="Check if the version of mscorlib.dll is less than 4.0.30319.18449" test_ref="oval:org.mitre.oval:tst:100689"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 4.5.1 is installed" definition_ref="oval:org.mitre.oval:def:22275"/>
        </criteria>
        <criteria operator="AND" comment=".NET 4.5.1 / Win 8.1 / Server 2012 R2">
          <criteria operator="OR" comment="Either OS">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criteria operator="OR" comment="ldr and gdr range">
            <criterion comment="Check if the version of mscorlib.dll is less than 4.0.30319.34011" test_ref="oval:org.mitre.oval:tst:100652"/>
            <criteria operator="AND" comment="ldr range for mscorlib.dll">
              <criterion comment="Check if the version of mscorlib.dll is less than 4.0.30319.36013" test_ref="oval:org.mitre.oval:tst:100709"/>
              <criterion comment="Check if the version of mscorlib.dll is greater than or equals to 4.0.30319.36000" test_ref="oval:org.mitre.oval:tst:100679"/>
            </criteria>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 4.5.1 is installed" definition_ref="oval:org.mitre.oval:def:22275"/>
        </criteria>
        <criteria operator="AND" comment=".NET 3.5.1 and Win 8.1 / 2012 R2">
          <criteria operator="OR" comment="Either OS">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 3.5 SP1 is installed" definition_ref="oval:org.mitre.oval:def:12542"/>
          <criterion comment="Check if the version of mscorlib.dll is less than 2.0.50727.8000" test_ref="oval:org.mitre.oval:tst:100668"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22465" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer Elevation of Privilege Vulnerability (CVE-2014-0268) - MS14-010</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-0268" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0268"/>
        <description>Microsoft Internet Explorer 8 through 11 does not properly restrict file installation and registry-key creation, which allows remote attackers to bypass the Mandatory Integrity Control protection mechanism via a crafted web site, aka "Internet Explorer Elevation of Privilege Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-02-17T12:48:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-02-19T08:12:47.741-05:00">DRAFT</status_change>
            <status_change date="2014-03-10T04:00:45.286-04:00">INTERIM</status_change>
            <status_change date="2014-03-31T04:00:26.583-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:22465 - extended definitions of OS are without SP checks" date="2014-07-28T18:06:00.495-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T18:08:42.271-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:02:20.947-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="ie8">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vista/2008/win7/2008r2//versions">
            <criteria operator="AND" comment="vista/2008/versions">
              <criteria operator="OR" comment="either os">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="gdr/ldr">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19499" test_ref="oval:org.mitre.oval:tst:100606"/>
                <criteria operator="AND" comment="ldr range">
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23562" test_ref="oval:org.mitre.oval:tst:100657"/>
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="win7/2008 r2/version">
              <criteria operator="OR" comment="either os">
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="gdr/ldr">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18365" test_ref="oval:org.mitre.oval:tst:100432"/>
                <criteria operator="AND" comment="ldr range">
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22567" test_ref="oval:org.mitre.oval:tst:100439"/>
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="xp/2003/version">
              <criteria operator="OR" comment="either os">
                <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
                <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23562" test_ref="oval:org.mitre.oval:tst:100657"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="ie9">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16533" test_ref="oval:org.mitre.oval:tst:100604"/>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20644" test_ref="oval:org.mitre.oval:tst:100436"/>
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
            </criteria>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
        </criteria>
        <criteria operator="AND" comment="ie10">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16798" test_ref="oval:org.mitre.oval:tst:100469"/>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.20916" test_ref="oval:org.mitre.oval:tst:100274"/>
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.20000" test_ref="oval:org.mitre.oval:tst:80523"/>
            </criteria>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
        </criteria>
        <criteria operator="AND" comment="ie11">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16518" test_ref="oval:org.mitre.oval:tst:100481"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22464" version="5" class="vulnerability">
      <metadata>
        <title>Memory corruption vulnerability in Microsoft Internet Explorer (CVE-2014-0287) - MS14-010</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-0287" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0287"/>
        <description>Microsoft Internet Explorer 8 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-0281.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-02-17T12:48:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-02-19T08:13:16.989-05:00">DRAFT</status_change>
            <status_change date="2014-03-10T04:00:45.128-04:00">INTERIM</status_change>
            <status_change date="2014-03-31T04:00:26.347-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:22464 - extended definitions of OS are without SP checks" date="2014-07-28T18:06:00.495-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T18:08:39.341-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:02:20.587-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="ie8">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vista/2008/win7/2008r2//versions">
            <criteria operator="AND" comment="vista/2008/versions">
              <criteria operator="OR" comment="either os">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="gdr/ldr">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19499" test_ref="oval:org.mitre.oval:tst:100606"/>
                <criteria operator="AND" comment="ldr range">
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23562" test_ref="oval:org.mitre.oval:tst:100657"/>
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="win7/2008 r2/version">
              <criteria operator="OR" comment="either os">
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="gdr/ldr">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18365" test_ref="oval:org.mitre.oval:tst:100432"/>
                <criteria operator="AND" comment="ldr range">
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22567" test_ref="oval:org.mitre.oval:tst:100439"/>
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="xp/2003/version">
              <criteria operator="OR" comment="either os">
                <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
                <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23562" test_ref="oval:org.mitre.oval:tst:100657"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="ie9">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16533" test_ref="oval:org.mitre.oval:tst:100604"/>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20644" test_ref="oval:org.mitre.oval:tst:100436"/>
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
            </criteria>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
        </criteria>
        <criteria operator="AND" comment="ie10">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16798" test_ref="oval:org.mitre.oval:tst:100469"/>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.20916" test_ref="oval:org.mitre.oval:tst:100274"/>
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.20000" test_ref="oval:org.mitre.oval:tst:80523"/>
            </criteria>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
        </criteria>
        <criteria operator="AND" comment="ie11">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16518" test_ref="oval:org.mitre.oval:tst:100481"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22456" version="7" class="vulnerability">
      <metadata>
        <title>Microsoft graphics component memory corruption vulnerability (CVE-2014-0263) - MS14-007</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-0263" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0263"/>
        <description>The Direct2D implementation in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to execute arbitrary code via a large 2D geometric figure that is encountered with Internet Explorer, aka "Microsoft Graphics Component Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-02-14T09:14:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-02-14T13:03:37.279-05:00">DRAFT</status_change>
            <status_change date="2014-03-03T04:01:09.304-05:00">INTERIM</status_change>
            <status_change date="2014-03-24T04:01:36.765-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:22456 - Corrected criteria associated with Windows 7 and 2008 R2" date="2014-04-18T14:40:00.222-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-04-18T14:43:26.446-04:00">INTERIM</status_change>
            <status_change date="2014-05-05T04:00:15.315-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Windows 7 / Server 2008 R2 and File">
          <criteria operator="OR" comment="Either OS">
            <extend_definition comment="Microsoft Windows 7 (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12292"/>
            <extend_definition comment="Microsoft Windows 7 x64 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12627"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12567"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Vulnerable File and Version">
            <criteria operator="AND" comment="gdr range">
              <criterion comment="Check if the version of D2d1.dll is greater than or equal to 6.1.7601.18000" test_ref="oval:org.mitre.oval:tst:113317"/>
              <criterion comment="Check if the version of D2d1.dll is less than 6.2.9200.16765" test_ref="oval:org.mitre.oval:tst:99737"/>
            </criteria>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of D2d1.dll is greater than or equal to 6.2.9200.20000" test_ref="oval:org.mitre.oval:tst:100095"/>
              <criterion comment="Check if the version of D2d1.dll is less than 6.2.9200.20883" test_ref="oval:org.mitre.oval:tst:99460"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Windows 8 / Server 2012 and File">
          <criteria operator="OR" comment="Either OS">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Vulnerable file version">
            <criterion comment="Check if the version of D2d1.dll is less than 6.2.9200.16765" test_ref="oval:org.mitre.oval:tst:99737"/>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of D2d1.dll is greater than or equal to 6.2.9200.20000" test_ref="oval:org.mitre.oval:tst:100095"/>
              <criterion comment="Check if the version of D2d1.dll is less than 6.2.9200.20882" test_ref="oval:org.mitre.oval:tst:99865"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Windows 8.1 / Server 2012 R2 and File">
          <criteria operator="OR" comment="Either os">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of D2d1.dll is less than 6.3.9600.16473" test_ref="oval:org.mitre.oval:tst:100215"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22443" version="5" class="vulnerability">
      <metadata>
        <title>Memory corruption vulnerability in Microsoft Internet Explorer (CVE-2014-0281) - MS14-010</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-0281" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0281"/>
        <description>Microsoft Internet Explorer 8 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-0287.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-02-17T12:48:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-02-19T08:12:34.694-05:00">DRAFT</status_change>
            <status_change date="2014-03-10T04:00:44.528-04:00">INTERIM</status_change>
            <status_change date="2014-03-31T04:00:25.234-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:22443 - extended definitions of OS are without SP checks" date="2014-07-28T18:06:00.495-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T18:08:40.371-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:02:19.832-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="ie8">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vista/2008/win7/2008r2//versions">
            <criteria operator="AND" comment="vista/2008/versions">
              <criteria operator="OR" comment="either os">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="gdr/ldr">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19499" test_ref="oval:org.mitre.oval:tst:100606"/>
                <criteria operator="AND" comment="ldr range">
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23562" test_ref="oval:org.mitre.oval:tst:100657"/>
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="win7/2008 r2/version">
              <criteria operator="OR" comment="either os">
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="gdr/ldr">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18365" test_ref="oval:org.mitre.oval:tst:100432"/>
                <criteria operator="AND" comment="ldr range">
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22567" test_ref="oval:org.mitre.oval:tst:100439"/>
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="xp/2003/version">
              <criteria operator="OR" comment="either os">
                <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
                <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23562" test_ref="oval:org.mitre.oval:tst:100657"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="ie9">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16533" test_ref="oval:org.mitre.oval:tst:100604"/>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20644" test_ref="oval:org.mitre.oval:tst:100436"/>
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
            </criteria>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
        </criteria>
        <criteria operator="AND" comment="ie10">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16798" test_ref="oval:org.mitre.oval:tst:100469"/>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.20916" test_ref="oval:org.mitre.oval:tst:100274"/>
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.20000" test_ref="oval:org.mitre.oval:tst:80523"/>
            </criteria>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
        </criteria>
        <criteria operator="AND" comment="ie11">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16518" test_ref="oval:org.mitre.oval:tst:100481"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22434" version="3" class="vulnerability">
      <metadata>
        <title>Unspecified vulnerability in the VirtualBox component in Oracle Virtualization VirtualBox 3.2.20, 4.0.22, 4.1.30, 4.2.20, and 4.3.4 allows local users to affect integrity and availability, a different vulnerability than CVE-2014-0404</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>VirtualBox</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-0406" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0406"/>
        <description>Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization VirtualBox prior to 3.2.20, 4.0.22, 4.1.30, 4.2.20, and 4.3.4 allows local users to affect integrity and availability via unknown vectors related to Core, a different vulnerability than CVE-2014-0404.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-17T08:31:03">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </submitted>
            <status_change date="2014-01-21T16:48:45.576-05:00">DRAFT</status_change>
            <status_change date="2014-02-10T04:00:27.944-05:00">INTERIM</status_change>
            <status_change date="2014-03-03T04:01:09.043-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="VirtualBox is installed" definition_ref="oval:org.mitre.oval:def:11581"/>
        <criterion comment="Check if Oracle VM VirtualBox is installed" test_ref="oval:org.mitre.oval:tst:42006"/>
        <criteria operator="OR" comment="Check versions of VirtualBox">
          <criteria operator="AND" comment="Affected versions of VirtualBox">
            <criterion comment="Check if Oracle VM VirtualBox version is greater than or equals to 3.2.0" test_ref="oval:org.mitre.oval:tst:88842"/>
            <criterion comment="Check if Oracle VM VirtualBox version is less than or equals to 3.2.18" test_ref="oval:org.mitre.oval:tst:100117"/>
          </criteria>
          <criteria operator="AND" comment="Affected versions of VirtualBox">
            <criterion comment="Check if Oracle VM VirtualBox version is greater than or equals to 4.0.0" test_ref="oval:org.mitre.oval:tst:88607"/>
            <criterion comment="Check if Oracle VM VirtualBox version is less than or equals to 4.0.20" test_ref="oval:org.mitre.oval:tst:100096"/>
          </criteria>
          <criteria operator="AND" comment="Affected versions of VirtualBox">
            <criterion comment="Check if Oracle VM VirtualBox version is greater than or equals to 4.1.0" test_ref="oval:org.mitre.oval:tst:88836"/>
            <criterion comment="Check if Oracle VM VirtualBox version is less than  or equals to 4.1.28" test_ref="oval:org.mitre.oval:tst:99957"/>
          </criteria>
          <criteria operator="AND" comment="Affected versions of VirtualBox">
            <criterion comment="Check if Oracle VM VirtualBox version is greater than or equals to 4.2.0" test_ref="oval:org.mitre.oval:tst:99857"/>
            <criterion comment="Check if Oracle VM VirtualBox version is less than  or equals to 4.2.18" test_ref="oval:org.mitre.oval:tst:99972"/>
          </criteria>
          <criteria operator="AND" comment="Affected versions of VirtualBox">
            <criterion comment="Check if Oracle VM VirtualBox version is greater than or equals to 4.3.0" test_ref="oval:org.mitre.oval:tst:100120"/>
            <criterion comment="Check if Oracle VM VirtualBox version is less than  or equals to 4.3.2" test_ref="oval:org.mitre.oval:tst:100166"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22409" version="3" class="vulnerability">
      <metadata>
        <title>Unspecified vulnerability in the VirtualBox component in Oracle Virtualization VirtualBox 3.2.20, 4.0.22, 4.1.30, 4.2.22, and 4.3.6 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Core.</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>VirtualBox</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2013-5892" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5892"/>
        <description>Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization VirtualBox prior to 3.2.20, 4.0.22, 4.1.30, 4.2.22, and 4.3.6 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Core.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-28T12:03:17">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </submitted>
            <status_change date="2014-01-30T14:49:20.533-05:00">DRAFT</status_change>
            <status_change date="2014-02-17T04:01:38.405-05:00">INTERIM</status_change>
            <status_change date="2014-03-10T04:00:43.864-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="VirtualBox is installed" definition_ref="oval:org.mitre.oval:def:11581"/>
        <criterion comment="Check if Oracle VM VirtualBox is installed" test_ref="oval:org.mitre.oval:tst:42006"/>
        <criteria operator="OR" comment="Check versions of VirtualBox">
          <criteria operator="AND" comment="Affected versions of VirtualBox">
            <criterion comment="Check if Oracle VM VirtualBox version is greater than or equals to 3.2.0" test_ref="oval:org.mitre.oval:tst:88842"/>
            <criterion comment="Check if Oracle VM VirtualBox version is less than or equals to 3.2.18" test_ref="oval:org.mitre.oval:tst:100117"/>
          </criteria>
          <criteria operator="AND" comment="Affected versions of VirtualBox">
            <criterion comment="Check if Oracle VM VirtualBox version is greater than or equals to 4.0.0" test_ref="oval:org.mitre.oval:tst:88607"/>
            <criterion comment="Check if Oracle VM VirtualBox version is less than or equals to 4.0.20" test_ref="oval:org.mitre.oval:tst:100096"/>
          </criteria>
          <criteria operator="AND" comment="Affected versions of VirtualBox">
            <criterion comment="Check if Oracle VM VirtualBox version is greater than or equals to 4.1.0" test_ref="oval:org.mitre.oval:tst:88836"/>
            <criterion comment="Check if Oracle VM VirtualBox version is less than  or equals to 4.1.28" test_ref="oval:org.mitre.oval:tst:99957"/>
          </criteria>
          <criteria operator="AND" comment="Affected versions of VirtualBox">
            <criterion comment="Check if Oracle VM VirtualBox version is greater than or equals to 4.2.0" test_ref="oval:org.mitre.oval:tst:99857"/>
            <criterion comment="Check if Oracle VM VirtualBox version is less than  or equals to 4.2.20" test_ref="oval:org.mitre.oval:tst:100260"/>
          </criteria>
          <criteria operator="AND" comment="Affected versions of VirtualBox">
            <criterion comment="Check if Oracle VM VirtualBox version is greater than or equals to 4.3.0" test_ref="oval:org.mitre.oval:tst:100120"/>
            <criterion comment="Check if Oracle VM VirtualBox version is less than  or equals to 4.3.4" test_ref="oval:org.mitre.oval:tst:100012"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22399" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability (CVE-2014-0309) - MS14-012</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-0309" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0309"/>
        <description>Microsoft Internet Explorer 8 through 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-03-13T06:57:21">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-03-14T10:59:04.188-04:00">DRAFT</status_change>
            <status_change date="2014-03-31T04:00:24.054-04:00">INTERIM</status_change>
            <status_change date="2014-04-21T04:00:24.613-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:22399 - extended definitions of OS are without SP checks" date="2014-07-28T18:08:00.084-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T18:10:10.864-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:02:19.382-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 8 and vulnerable file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="Check for vulnerable OS and files">
            <criteria operator="AND" comment="XP / 2k3 and vulnerable file version">
              <criteria operator="OR" comment="XP / 2K3">
                <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
                <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23569" test_ref="oval:org.mitre.oval:tst:100829"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista / 2K8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19507" test_ref="oval:org.mitre.oval:tst:100836"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23569" test_ref="oval:org.mitre.oval:tst:100829"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vulnerable file version">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18392" test_ref="oval:org.mitre.oval:tst:100526"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22597" test_ref="oval:org.mitre.oval:tst:100560"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 and vulnerable file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="Win 7 / R2 / Vista / 2K8">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16540" test_ref="oval:org.mitre.oval:tst:100887"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20651" test_ref="oval:org.mitre.oval:tst:100703"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 and vulnerable file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7 / R2/ Win 8 / 2K12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16843" test_ref="oval:org.mitre.oval:tst:100896"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.20000" test_ref="oval:org.mitre.oval:tst:80523"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.20963" test_ref="oval:org.mitre.oval:tst:100791"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22391" version="3" class="vulnerability">
      <metadata>
        <title>Unspecified vulnerability in the VirtualBox component in Oracle Virtualization VirtualBox 3.2.20, 4.0.22, 4.1.30, 4.2.20, and 4.3.4 allows local users to affect integrity and availability, a different vulnerability than CVE-2014-0406</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>VirtualBox</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-0404" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0404"/>
        <description>Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization VirtualBox prior to 3.2.20, 4.0.22, 4.1.30, 4.2.20, and 4.3.4 allows local users to affect integrity and availability via unknown vectors related to Core, a different vulnerability than CVE-2014-0406.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-17T08:31:03">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </submitted>
            <status_change date="2014-01-21T16:48:45.953-05:00">DRAFT</status_change>
            <status_change date="2014-02-10T04:00:27.690-05:00">INTERIM</status_change>
            <status_change date="2014-03-03T04:01:07.094-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="VirtualBox is installed" definition_ref="oval:org.mitre.oval:def:11581"/>
        <criterion comment="Check if Oracle VM VirtualBox is installed" test_ref="oval:org.mitre.oval:tst:42006"/>
        <criteria operator="OR" comment="Check versions of VirtualBox">
          <criteria operator="AND" comment="Affected versions of VirtualBox">
            <criterion comment="Check if Oracle VM VirtualBox version is greater than or equals to 3.2.0" test_ref="oval:org.mitre.oval:tst:88842"/>
            <criterion comment="Check if Oracle VM VirtualBox version is less than or equals to 3.2.18" test_ref="oval:org.mitre.oval:tst:100117"/>
          </criteria>
          <criteria operator="AND" comment="Affected versions of VirtualBox">
            <criterion comment="Check if Oracle VM VirtualBox version is greater than or equals to 4.0.0" test_ref="oval:org.mitre.oval:tst:88607"/>
            <criterion comment="Check if Oracle VM VirtualBox version is less than or equals to 4.0.20" test_ref="oval:org.mitre.oval:tst:100096"/>
          </criteria>
          <criteria operator="AND" comment="Affected versions of VirtualBox">
            <criterion comment="Check if Oracle VM VirtualBox version is greater than or equals to 4.1.0" test_ref="oval:org.mitre.oval:tst:88836"/>
            <criterion comment="Check if Oracle VM VirtualBox version is less than  or equals to 4.1.28" test_ref="oval:org.mitre.oval:tst:99957"/>
          </criteria>
          <criteria operator="AND" comment="Affected versions of VirtualBox">
            <criterion comment="Check if Oracle VM VirtualBox version is greater than or equals to 4.2.0" test_ref="oval:org.mitre.oval:tst:99857"/>
            <criterion comment="Check if Oracle VM VirtualBox version is less than  or equals to 4.2.18" test_ref="oval:org.mitre.oval:tst:99972"/>
          </criteria>
          <criteria operator="AND" comment="Affected versions of VirtualBox">
            <criterion comment="Check if Oracle VM VirtualBox version is greater than or equals to 4.3.0" test_ref="oval:org.mitre.oval:tst:100120"/>
            <criterion comment="Check if Oracle VM VirtualBox version is less than  or equals to 4.3.2" test_ref="oval:org.mitre.oval:tst:100166"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22385" version="5" class="vulnerability">
      <metadata>
        <title>Memory corruption vulnerability in Microsoft Internet Explorer (CVE-2014-0273) - MS14-010</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-0273" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0273"/>
        <description>Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-0270, CVE-2014-0274, and CVE-2014-0288.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-02-17T12:48:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-02-19T08:13:06.923-05:00">DRAFT</status_change>
            <status_change date="2014-03-10T04:00:43.202-04:00">INTERIM</status_change>
            <status_change date="2014-03-31T04:00:23.536-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:22385 - extended definitions of OS are without SP checks" date="2014-07-28T18:06:00.495-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T18:08:41.861-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:02:18.846-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="ie9">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16533" test_ref="oval:org.mitre.oval:tst:100604"/>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20644" test_ref="oval:org.mitre.oval:tst:100436"/>
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
            </criteria>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
        </criteria>
        <criteria operator="AND" comment="ie10">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16798" test_ref="oval:org.mitre.oval:tst:100469"/>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.20916" test_ref="oval:org.mitre.oval:tst:100274"/>
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.20000" test_ref="oval:org.mitre.oval:tst:80523"/>
            </criteria>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
        </criteria>
        <criteria operator="AND" comment="ie11">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16518" test_ref="oval:org.mitre.oval:tst:100481"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22381" version="5" class="vulnerability">
      <metadata>
        <title>Memory corruption vulnerability in Microsoft Internet Explorer (CVE-2014-0269) - MS14-010</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-0269" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0269"/>
        <description>Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-02-17T12:48:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-02-19T08:12:45.486-05:00">DRAFT</status_change>
            <status_change date="2014-03-10T04:00:43.015-04:00">INTERIM</status_change>
            <status_change date="2014-03-31T04:00:23.285-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:22381 - extended definitions of OS are without SP checks" date="2014-07-28T18:06:00.495-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T18:08:42.804-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:02:18.545-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="ie6">
          <criteria operator="OR" comment="xp/2003">
            <criteria operator="AND" comment="ie6/xp/version">
              <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
              <criterion comment="Check if the version of mshtml.dll is less than 6.0.2900.6498" test_ref="oval:org.mitre.oval:tst:100192"/>
            </criteria>
            <criteria operator="AND" comment="ie6/xp/2003/versions">
              <criteria operator="OR" comment="xp/2003">
                <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
                <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5281" test_ref="oval:org.mitre.oval:tst:100478"/>
            </criteria>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
        </criteria>
        <criteria operator="AND" comment="ie7">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="xp/2003/vista/2008/">
            <criteria operator="AND" comment="xp/2003/version">
              <criteria operator="OR" comment="either os">
                <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
                <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
                <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21366" test_ref="oval:org.mitre.oval:tst:100587"/>
            </criteria>
            <criteria operator="AND" comment="vista/2008/version">
              <criteria operator="OR" comment="either os">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="gdr/ldr">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19016" test_ref="oval:org.mitre.oval:tst:100315"/>
                <criteria operator="AND" comment="ldr range">
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23303" test_ref="oval:org.mitre.oval:tst:100212"/>
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="ie8">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vista/2008/win7/2008r2//versions">
            <criteria operator="AND" comment="vista/2008/versions">
              <criteria operator="OR" comment="either os">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="gdr/ldr">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19499" test_ref="oval:org.mitre.oval:tst:100606"/>
                <criteria operator="AND" comment="ldr range">
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23562" test_ref="oval:org.mitre.oval:tst:100657"/>
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="win7/2008 r2/version">
              <criteria operator="OR" comment="either os">
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="gdr/ldr">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18365" test_ref="oval:org.mitre.oval:tst:100432"/>
                <criteria operator="AND" comment="ldr range">
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22567" test_ref="oval:org.mitre.oval:tst:100439"/>
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="xp/2003/version">
              <criteria operator="OR" comment="either os">
                <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
                <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23562" test_ref="oval:org.mitre.oval:tst:100657"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="ie9">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16533" test_ref="oval:org.mitre.oval:tst:100604"/>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20644" test_ref="oval:org.mitre.oval:tst:100436"/>
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
            </criteria>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
        </criteria>
        <criteria operator="AND" comment="ie10">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16798" test_ref="oval:org.mitre.oval:tst:100469"/>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.20916" test_ref="oval:org.mitre.oval:tst:100274"/>
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.20000" test_ref="oval:org.mitre.oval:tst:80523"/>
            </criteria>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22338" version="5" class="vulnerability">
      <metadata>
        <title>Memory corruption vulnerability in Microsoft Internet Explorer (CVE-2014-0274) - MS14-010</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-0274" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0274"/>
        <description>Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-0270, CVE-2014-0273, and CVE-2014-0288.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-02-17T12:48:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-02-19T08:12:50.740-05:00">DRAFT</status_change>
            <status_change date="2014-03-10T04:00:42.575-04:00">INTERIM</status_change>
            <status_change date="2014-03-31T04:00:22.503-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:22338 - extended definitions of OS are without SP checks" date="2014-07-28T18:06:00.495-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T18:08:41.140-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:02:17.788-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="ie9">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16533" test_ref="oval:org.mitre.oval:tst:100604"/>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20644" test_ref="oval:org.mitre.oval:tst:100436"/>
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
            </criteria>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
        </criteria>
        <criteria operator="AND" comment="ie10">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16798" test_ref="oval:org.mitre.oval:tst:100469"/>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.20916" test_ref="oval:org.mitre.oval:tst:100274"/>
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.20000" test_ref="oval:org.mitre.oval:tst:80523"/>
            </criteria>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
        </criteria>
        <criteria operator="AND" comment="ie11">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16518" test_ref="oval:org.mitre.oval:tst:100481"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22335" version="5" class="vulnerability">
      <metadata>
        <title>Memory corruption vulnerability in Microsoft Internet Explorer (CVE-2014-0270) - MS14-010</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-0270" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0270"/>
        <description>Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-0273, CVE-2014-0274, and CVE-2014-0288.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-02-17T12:48:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-02-19T08:13:09.447-05:00">DRAFT</status_change>
            <status_change date="2014-03-10T04:00:42.445-04:00">INTERIM</status_change>
            <status_change date="2014-03-31T04:00:22.232-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:22335 - extended definitions of OS are without SP checks" date="2014-07-28T18:06:00.495-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T18:08:37.146-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:02:17.511-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="ie9">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16533" test_ref="oval:org.mitre.oval:tst:100604"/>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20644" test_ref="oval:org.mitre.oval:tst:100436"/>
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
            </criteria>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
        </criteria>
        <criteria operator="AND" comment="ie10">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16798" test_ref="oval:org.mitre.oval:tst:100469"/>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.20916" test_ref="oval:org.mitre.oval:tst:100274"/>
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.20000" test_ref="oval:org.mitre.oval:tst:80523"/>
            </criteria>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
        </criteria>
        <criteria operator="AND" comment="ie11">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16518" test_ref="oval:org.mitre.oval:tst:100481"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22326" version="10" class="vulnerability">
      <metadata>
        <title>Vulnerability in Microsoft XML Core Services could allow information disclosure (CVE-2014-0266) - MS14-005</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft XML Core Services 3.0</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-0266" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0266"/>
        <description>The XMLHTTP ActiveX controls in XML Core Services 3.0 in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allow remote attackers to bypass the Same Origin Policy via a web page that is visited in Internet Explorer, aka "MSXML Information Disclosure Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-02-14T09:35:14">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-02-14T12:57:27.524-05:00">DRAFT</status_change>
            <status_change date="2014-03-03T04:01:06.046-05:00">INTERIM</status_change>
            <status_change date="2014-03-24T04:01:34.225-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:19706 - comment has been updated from &quot;less than&quot; to &quot;greater than or equal&quot;" date="2014-06-20T11:02:00.031-04:00">
              <contributor organization="SecPod Technologies">Saurabh Kumar</contributor>
            </modified>
            <status_change date="2014-06-20T11:04:15.482-04:00">INTERIM</status_change>
            <status_change date="2014-07-07T04:00:54.725-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:22326 - extended definitions of OS are without SP checks" date="2014-07-28T18:06:00.495-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T18:08:38.452-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:02:17.224-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Microsoft XML Core Services 3 is installed" definition_ref="oval:org.mitre.oval:def:415"/>
        <criteria operator="OR" comment="vulnerable os versions">
          <criteria operator="AND" comment="win8/2012/versions">
            <criteria operator="OR" comment="either os">
              <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
              <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
              <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
            </criteria>
            <criteria operator="OR" comment="gdr/ldr">
              <criterion comment="Check if the version of Msxml3.dll is less than 8.110.9200.16772" test_ref="oval:org.mitre.oval:tst:99868"/>
              <criteria operator="AND" comment="ldr range">
                <criterion comment="Check if the version of Msxml3.dll is less than 8.110.9200.20890" test_ref="oval:org.mitre.oval:tst:100332"/>
                <criterion comment="Check if the version of msxml3.dll is greater than or equal to 8.110.9200.20000" test_ref="oval:org.mitre.oval:tst:80548"/>
              </criteria>
            </criteria>
          </criteria>
          <criteria operator="AND" comment="win 8.1/2012 r2/versions">
            <criteria operator="OR" comment="either os">
              <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
              <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
              <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            </criteria>
            <criterion comment="Check if the version of Msxml3.dll is less than 8.110.9600.16483" test_ref="oval:org.mitre.oval:tst:99763"/>
          </criteria>
          <criteria operator="AND" comment="win xp/2003/version">
            <criteria operator="OR" comment="either os">
              <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
              <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
              <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
              <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
              <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            </criteria>
            <criterion comment="Check if the version of Msxml3.dll is less than 8.100.1054.0" test_ref="oval:org.mitre.oval:tst:100025"/>
          </criteria>
          <criteria operator="AND" comment="vista/2008/versions">
            <criteria operator="OR" comment="either os">
              <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
              <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
              <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
              <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            </criteria>
            <criterion comment="Check if the version of Msxml3.dll is less than 8.100.5007.0" test_ref="oval:org.mitre.oval:tst:100196"/>
          </criteria>
          <criteria operator="AND" comment="win7/2008 r2/versions">
            <criteria operator="OR" comment="either os">
              <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
              <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
              <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            </criteria>
            <criteria operator="OR" comment="gdr/ldr">
              <criterion comment="Check if the version of Msxml3.dll is less than 8.110.7601.18334" test_ref="oval:org.mitre.oval:tst:100013"/>
              <criteria operator="AND" comment="ldr range">
                <criterion comment="Check if the version of Msxml3.dll is less than 8.110.7601.22532" test_ref="oval:org.mitre.oval:tst:100396"/>
                <criterion comment="Check if version of Msxml3.dll is greater than or equal to 8.110.7601.22000" test_ref="oval:org.mitre.oval:tst:79072"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:415" version="3" class="inventory">
      <metadata>
        <title>Microsoft XML Core Services 3 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft XML Core Services 3</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:xml_core_services:3"/>
        <description>Microsoft XML Core Services 3 is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-10-11T05:29:41">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-10-13T14:55:00.00-04:00">DRAFT</status_change>
            <status_change date="2006-10-31T19:35:39.106-05:00">INTERIM</status_change>
            <status_change date="2006-11-21T21:27:48.903-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:415 - products added to inventories" date="2015-04-17T09:39:00.289-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-04-17T09:41:23.535-04:00">INTERIM</status_change>
            <status_change date="2015-05-04T04:00:19.498-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="Microsoft XML Core Services 3 is installed." test_ref="oval:org.mitre.oval:tst:179"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22316" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability (CVE-2014-0321) - MS14-012</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-0321" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0321"/>
        <description>Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-0313.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-03-13T06:57:21">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-03-14T10:58:38.702-04:00">DRAFT</status_change>
            <status_change date="2014-03-31T04:00:22.001-04:00">INTERIM</status_change>
            <status_change date="2014-04-21T04:00:24.186-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:22316 - extended definitions of OS are without SP checks" date="2014-07-28T18:08:00.084-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T18:10:12.039-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:02:17.049-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 10 and vulnerable file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7 / R2/ Win 8 / 2K12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16843" test_ref="oval:org.mitre.oval:tst:100896"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.20000" test_ref="oval:org.mitre.oval:tst:80523"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.20963" test_ref="oval:org.mitre.oval:tst:100791"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 and vulnerable file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7 / R2/ Win 8.1 / 2K12 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16521" test_ref="oval:org.mitre.oval:tst:100855"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22314" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer Cross-domain Information Disclosure Vulnerability - CVE-2014-0293 - MS14-010</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-0293" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0293"/>
        <description>Microsoft Internet Explorer 9 through 11 allows remote attackers to read content from a different (1) domain or (2) zone via a crafted web site, aka "Internet Explorer Cross-domain Information Disclosure Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-02-17T12:48:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-02-19T08:12:40.273-05:00">DRAFT</status_change>
            <status_change date="2014-03-10T04:00:42.184-04:00">INTERIM</status_change>
            <status_change date="2014-03-31T04:00:21.797-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:22314 - extended definitions of OS are without SP checks" date="2014-07-28T18:06:00.495-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T18:08:40.588-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:02:16.803-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="ie9">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16533" test_ref="oval:org.mitre.oval:tst:100604"/>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20644" test_ref="oval:org.mitre.oval:tst:100436"/>
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
            </criteria>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
        </criteria>
        <criteria operator="AND" comment="ie10">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16798" test_ref="oval:org.mitre.oval:tst:100469"/>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.20916" test_ref="oval:org.mitre.oval:tst:100274"/>
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.20000" test_ref="oval:org.mitre.oval:tst:80523"/>
            </criteria>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
        </criteria>
        <criteria operator="AND" comment="ie11">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16518" test_ref="oval:org.mitre.oval:tst:100481"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22283" version="8" class="vulnerability">
      <metadata>
        <title>POST Request DoS Vulnerability (CVE-2014-0253) - MS14-009</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft .NET Framework 1.1</product>
          <product>Microsoft .NET Framework 2.0</product>
          <product>Microsoft .NET Framework 3.0</product>
          <product>Microsoft .NET Framework 3.5.1</product>
          <product>Microsoft .NET Framework 4.0</product>
          <product>Microsoft .NET Framework 4.5</product>
          <product>Microsoft .NET Framework 4.5.1</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-0253" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0253"/>
        <description>Microsoft .NET Framework 1.1 SP1, 2.0 SP2, 3.5, 3.5.1, 4, 4.5, and 4.5.1 does not properly determine TCP connection states, which allows remote attackers to cause a denial of service (ASP.NET daemon hang) via crafted HTTP requests that trigger persistent resource consumption for a (1) stale or (2) closed connection, as exploited in the wild in February 2014, aka "POST Request DoS Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-02-18T02:39:12">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-02-19T08:22:22.700-05:00">DRAFT</status_change>
            <status_change date="2014-03-10T04:00:41.127-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:22283 - extend definition was changed to oval:org.mitre.oval:def:6689 in two criteria according Microsoft Security Bulletin." date="2014-03-19T14:00:00.561-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:def:22283 - def:22283 criteria updated .net 3.5 replaced with 3.5 sp1 to avoid FN" date="2014-03-27T12:44:00.575-04:00">
              <contributor organization="SecPod Technologies">Kumarswamy S</contributor>
            </modified>
            <status_change date="2014-04-14T04:00:11.272-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:22283 - extended definitions of OS are without SP checks" date="2014-07-28T18:06:00.495-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T18:08:40.851-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:02:16.345-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment=".net 2.0 sp2/xp/server 2003/versions">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 2.0 Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6158"/>
          <criteria operator="OR" comment="either file versions GDR/LDR">
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of system.web.dll is less than 2.0.50727.7046" test_ref="oval:org.mitre.oval:tst:100093"/>
              <criterion comment="Check if the version of system.web.dll is greater than or equal to 2.0.50727.7000" test_ref="oval:org.mitre.oval:tst:100649"/>
            </criteria>
            <criterion comment="Check if the version of System.Web.dll is less than 2.0.50727.3658" test_ref="oval:org.mitre.oval:tst:100508"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment=".net 2.0 sp2/vista/server 2008/versions">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 2.0 Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6158"/>
          <criteria operator="OR" comment="either file versions">
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of system.web.dll is less than 2.0.50727.7045" test_ref="oval:org.mitre.oval:tst:100485"/>
              <criterion comment="Check if the version of system.web.dll is greater than or equal to 2.0.50727.7000" test_ref="oval:org.mitre.oval:tst:100649"/>
            </criteria>
            <criterion comment="Check if the version of system.web.dll is less than 2.0.50727.4248" test_ref="oval:org.mitre.oval:tst:100586"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment=".net 3.5/win 8/server 2012/versions">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
          </criteria>
          <criteria operator="OR" comment="either file versions">
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of system.web.dll is less than 2.0.50727.7045" test_ref="oval:org.mitre.oval:tst:100485"/>
              <criterion comment="Check if the version of system.web.dll is greater than or equal to 2.0.50727.7000" test_ref="oval:org.mitre.oval:tst:100649"/>
            </criteria>
            <criterion comment="Check if the version of the system.web.dll is less than 2.0.50727.6414" test_ref="oval:org.mitre.oval:tst:100584"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 3.5 SP1 is installed" definition_ref="oval:org.mitre.oval:def:12542"/>
        </criteria>
        <criteria operator="AND" comment=".net 3.5.1/win 7/server 2008 R2/versions">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 3.5 SP1 is installed" definition_ref="oval:org.mitre.oval:def:12542"/>
          <criteria operator="OR" comment="either file versions">
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of system.web.dll is less than 2.0.50727.7045" test_ref="oval:org.mitre.oval:tst:100485"/>
              <criterion comment="Check if the version of system.web.dll is greater than or equal to 2.0.50727.7000" test_ref="oval:org.mitre.oval:tst:100649"/>
            </criteria>
            <criterion comment="Check if the version of system.web.dll is less than 2.0.50727.5479" test_ref="oval:org.mitre.oval:tst:100354"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment=".net 4.0/win xp.server 2003/vista/server 2008/win 7/server 2008 R2/versions">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6749"/>
          <criteria operator="OR" comment="either file versions">
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of Setup.exe is less than 10.0.30319.2034" test_ref="oval:org.mitre.oval:tst:100527"/>
              <criterion comment="Check if the version of Setup.exe is greater than or equal to 10.0.30319.2000" test_ref="oval:org.mitre.oval:tst:100142"/>
            </criteria>
            <criterion comment="Check if the version of Setup.exe is less than 10.0.30319.1022" test_ref="oval:org.mitre.oval:tst:100707"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment=".net 4.5/vista/server 2008/win 7/server 2008 R2/versions">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 4.5 is installed" definition_ref="oval:org.mitre.oval:def:15925"/>
          <criteria operator="OR" comment="either file versions">
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of system.web.dll is less than 4.0.30319.19136" test_ref="oval:org.mitre.oval:tst:100040"/>
              <criterion comment="Check if the version of system.web.dll is greater than or equal to 4.0.30319.19000" test_ref="oval:org.mitre.oval:tst:100075"/>
            </criteria>
            <criterion comment="Check if the version of system.web.dll is less than 4.0.30319.18067" test_ref="oval:org.mitre.oval:tst:99901"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment=".net 4.5/win 8/server 2012/versions">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 4.5 is installed" definition_ref="oval:org.mitre.oval:def:15925"/>
          <criteria operator="OR" comment="either file versions">
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of system.web.dll is less than 4.0.30319.19455" test_ref="oval:org.mitre.oval:tst:100618"/>
              <criterion comment="Check if the version of system.web.dll is greater than or equal to 4.0.30319.19000" test_ref="oval:org.mitre.oval:tst:100075"/>
            </criteria>
            <criterion comment="Check if the version of system.web.dll is less than 4.0.30319.18449" test_ref="oval:org.mitre.oval:tst:100654"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment=".NET 1.1 and vulnerable file">
          <extend_definition comment="Microsoft .NET Framework 1.1 Service Pack 1 is Installed" definition_ref="oval:org.mitre.oval:def:1834"/>
          <criterion comment="Check if the version of System.web.dll is less than 1.1.4322.2505" test_ref="oval:org.mitre.oval:tst:99773"/>
          <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
        </criteria>
        <criteria operator="AND" comment=".NET 4.5.1 and Win Vista / 7 / 2008 / 2008R2">
          <criteria operator="OR" comment="Either OS">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
          </criteria>
          <criterion comment="Check if the version of system.web.dll is less than 4.0.30319.18446" test_ref="oval:org.mitre.oval:tst:100385"/>
          <extend_definition comment="Microsoft .NET Framework 4.5.1 is installed" definition_ref="oval:org.mitre.oval:def:22275"/>
        </criteria>
        <criteria operator="AND" comment=".NET 4.5.1 and Win 8 / Server 2012">
          <criteria operator="OR" comment="Either OS">
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="gdr and ldr range">
            <criterion comment="Check if the version of system.web.dll is less than 4.0.30319.18447" test_ref="oval:org.mitre.oval:tst:100018"/>
            <criteria operator="AND" comment="ldr range for system.web.dll">
              <criterion comment="Check if the version of system.web.dll is greater than or equal to 4.0.30319.19000" test_ref="oval:org.mitre.oval:tst:100075"/>
              <criterion comment="Check if the version of system.web.dll is less than 4.0.30319.19453" test_ref="oval:org.mitre.oval:tst:100658"/>
            </criteria>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 4.5.1 is installed" definition_ref="oval:org.mitre.oval:def:22275"/>
        </criteria>
        <criteria operator="AND" comment=".NET 4.5.1 / Win 8.1 / Server 2012 R2">
          <criteria operator="OR" comment="Either OS">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of system.web.dll is less than 4.0.30319.34009" test_ref="oval:org.mitre.oval:tst:100407"/>
          <extend_definition comment="Microsoft .NET Framework 4.5.1 is installed" definition_ref="oval:org.mitre.oval:def:22275"/>
        </criteria>
        <criteria operator="AND" comment=".NET 3.5 and Win 8.1 / 2012 R2">
          <criteria operator="OR" comment="Either OS">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of system.web.dll is less than 2.0.50727.8001" test_ref="oval:org.mitre.oval:tst:100140"/>
          <extend_definition comment="Microsoft .NET Framework 3.5 SP1 is installed" definition_ref="oval:org.mitre.oval:def:12542"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22275" version="4" class="inventory">
      <metadata>
        <title>Microsoft .NET Framework 4.5.1 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <product>Microsoft .NET Framework 4.5.1</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:.net_framework:4.5.1"/>
        <description>Microsoft .NET Framework 4.5.1 is installed</description>
        <oval_repository>
          <dates>
            <submitted date="2014-02-07T13:00:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </submitted>
            <status_change date="2014-02-07T11:56:43.215-05:00">DRAFT</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:100133 - MS14-009 bulletin, def:22275 updated to check release instead of version" date="2014-02-19T08:13:00.375-05:00">
              <contributor organization="SecPod Technologies">Pooja Shetty</contributor>
            </modified>
            <status_change date="2014-03-10T04:00:41.051-04:00">INTERIM</status_change>
            <status_change date="2014-03-31T04:00:20.604-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="Either release version">
          <criterion comment="Check if the release version of .Net framework 4.5.1 (full) is equal to 378675" test_ref="oval:org.mitre.oval:tst:100228"/>
          <criterion comment="Check if the release version of .Net framework 4.5 (full) is equal to 378758" test_ref="oval:org.mitre.oval:tst:99926"/>
        </criteria>
        <criteria operator="OR" comment="Either release version">
          <criterion comment="Check if the release version of .Net framework 4.5.1 (client) is equal to 378758" test_ref="oval:org.mitre.oval:tst:100133"/>
          <criterion comment="Check if the release version of .Net framework 4.5 (client) is equal 378675" test_ref="oval:org.mitre.oval:tst:100516"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22252" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability (CVE-2014-0324) - MS14-012</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-0324" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0324"/>
        <description>Microsoft Internet Explorer 8 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-0297, CVE-2014-0308, and CVE-2014-0312.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-03-13T06:57:21">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-03-14T10:58:51.841-04:00">DRAFT</status_change>
            <status_change date="2014-03-31T04:00:19.874-04:00">INTERIM</status_change>
            <status_change date="2014-04-21T04:00:23.661-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:22252 - extended definitions of OS are without SP checks" date="2014-07-28T18:08:00.084-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T18:10:07.668-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:02:16.059-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 8 and vulnerable file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="Check for vulnerable OS and files">
            <criteria operator="AND" comment="XP / 2k3 and vulnerable file version">
              <criteria operator="OR" comment="XP / 2K3">
                <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
                <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23569" test_ref="oval:org.mitre.oval:tst:100829"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista / 2K8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19507" test_ref="oval:org.mitre.oval:tst:100836"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23569" test_ref="oval:org.mitre.oval:tst:100829"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vulnerable file version">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18392" test_ref="oval:org.mitre.oval:tst:100526"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22597" test_ref="oval:org.mitre.oval:tst:100560"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 and vulnerable file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="Win 7 / R2 / Vista / 2K8">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16540" test_ref="oval:org.mitre.oval:tst:100887"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20651" test_ref="oval:org.mitre.oval:tst:100703"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 and vulnerable file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7 / R2/ Win 8 / 2K12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16843" test_ref="oval:org.mitre.oval:tst:100896"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.20000" test_ref="oval:org.mitre.oval:tst:80523"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.20963" test_ref="oval:org.mitre.oval:tst:100791"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 and vulnerable file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7 / R2/ Win 8.1 / 2K12 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16521" test_ref="oval:org.mitre.oval:tst:100855"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22236" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability (CVE-2014-0314) - MS14-012</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-0314" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0314"/>
        <description>Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-03-13T06:57:21">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-03-14T10:58:37.618-04:00">DRAFT</status_change>
            <status_change date="2014-03-31T04:00:19.314-04:00">INTERIM</status_change>
            <status_change date="2014-04-21T04:00:23.424-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:22236 - extended definitions of OS are without SP checks" date="2014-07-28T18:08:00.084-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T18:10:10.087-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:02:15.868-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 9 and vulnerable file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="Win 7 / R2 / Vista / 2K8">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16540" test_ref="oval:org.mitre.oval:tst:100887"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20651" test_ref="oval:org.mitre.oval:tst:100703"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 and vulnerable file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7 / R2/ Win 8 / 2K12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16843" test_ref="oval:org.mitre.oval:tst:100896"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.20000" test_ref="oval:org.mitre.oval:tst:80523"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.20963" test_ref="oval:org.mitre.oval:tst:100791"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22077" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability (CVE-2014-0311) - MS14-012</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-0311" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0311"/>
        <description>Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-0299 and CVE-2014-0305.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-03-13T06:57:21">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-03-14T10:58:41.210-04:00">DRAFT</status_change>
            <status_change date="2014-03-31T04:00:15.478-04:00">INTERIM</status_change>
            <status_change date="2014-04-21T04:00:21.607-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:22077 - extended definitions of OS are without SP checks" date="2014-07-28T18:08:00.084-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T18:10:08.116-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:02:14.102-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 and vulnerable file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="Check for vulnerable OS and files">
            <criteria operator="AND" comment="XP 32 bit and vulnerable file version">
              <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
              <criterion comment="Check if the version of mshtml.dll is less than 6.0.2900.6512" test_ref="oval:org.mitre.oval:tst:99906"/>
            </criteria>
            <criteria operator="AND" comment="XP X64 / 2k3 and vulnerable file version">
              <criteria operator="OR" comment="XP x64 / 2k3">
                <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5294" test_ref="oval:org.mitre.oval:tst:100280"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 7 and vulnerable file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="Check for vulnerable OS and files">
            <criteria operator="AND" comment="XP / 2k3 and vulnerable file version">
              <criteria operator="OR" comment="XP / 2K3">
                <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
                <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21371" test_ref="oval:org.mitre.oval:tst:100174"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2K8 and vulnerable file version">
              <criteria operator="OR" comment="Vista / 2K8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19041" test_ref="oval:org.mitre.oval:tst:100257"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23330" test_ref="oval:org.mitre.oval:tst:100536"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 and vulnerable file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="Check for vulnerable OS and files">
            <criteria operator="AND" comment="XP / 2k3 and vulnerable file version">
              <criteria operator="OR" comment="XP / 2K3">
                <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
                <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23569" test_ref="oval:org.mitre.oval:tst:100829"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista / 2K8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19507" test_ref="oval:org.mitre.oval:tst:100836"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23569" test_ref="oval:org.mitre.oval:tst:100829"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / 2k8 R2 and vulnerable file version">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18392" test_ref="oval:org.mitre.oval:tst:100526"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22597" test_ref="oval:org.mitre.oval:tst:100560"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 and vulnerable file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="Win 7 / R2 / Vista / 2K8">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16540" test_ref="oval:org.mitre.oval:tst:100887"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20651" test_ref="oval:org.mitre.oval:tst:100703"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 and vulnerable file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7 / R2/ Win 8 / 2K12">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16843" test_ref="oval:org.mitre.oval:tst:100896"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.20000" test_ref="oval:org.mitre.oval:tst:80523"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.20963" test_ref="oval:org.mitre.oval:tst:100791"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 and vulnerable file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 7 / R2/ Win 8.1 / 2K12 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16521" test_ref="oval:org.mitre.oval:tst:100855"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21998" version="5" class="vulnerability">
      <metadata>
        <title>Memory corruption vulnerability in Microsoft Internet Explorer (CVE-2014-0272) - MS14-010</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-0272" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0272"/>
        <description>Microsoft Internet Explorer 8 through 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-02-17T12:48:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-02-19T08:12:58.746-05:00">DRAFT</status_change>
            <status_change date="2014-03-10T04:00:36.801-04:00">INTERIM</status_change>
            <status_change date="2014-03-31T04:00:13.955-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:21998 - extended definitions of OS are without SP checks" date="2014-07-28T18:06:00.495-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T18:08:42.505-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:02:12.787-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="ie8">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vista/2008/win7/2008r2//versions">
            <criteria operator="AND" comment="vista/2008/versions">
              <criteria operator="OR" comment="either os">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="gdr/ldr">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19499" test_ref="oval:org.mitre.oval:tst:100606"/>
                <criteria operator="AND" comment="ldr range">
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23562" test_ref="oval:org.mitre.oval:tst:100657"/>
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="win7/2008 r2/version">
              <criteria operator="OR" comment="either os">
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="gdr/ldr">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18365" test_ref="oval:org.mitre.oval:tst:100432"/>
                <criteria operator="AND" comment="ldr range">
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22567" test_ref="oval:org.mitre.oval:tst:100439"/>
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="xp/2003/version">
              <criteria operator="OR" comment="either os">
                <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
                <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23562" test_ref="oval:org.mitre.oval:tst:100657"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="ie9">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16533" test_ref="oval:org.mitre.oval:tst:100604"/>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20644" test_ref="oval:org.mitre.oval:tst:100436"/>
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
            </criteria>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
        </criteria>
        <criteria operator="AND" comment="ie10">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16798" test_ref="oval:org.mitre.oval:tst:100469"/>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.20916" test_ref="oval:org.mitre.oval:tst:100274"/>
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.20000" test_ref="oval:org.mitre.oval:tst:80523"/>
            </criteria>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21883" version="3" class="vulnerability">
      <metadata>
        <title>Unspecified vulnerability in the VirtualBox component in Oracle Virtualization VirtualBox 3.2.20, 4.0.22, 4.1.30, 4.2.20, and 4.3.4 allows local users to affect confidentiality, integrity, and availability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>VirtualBox</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-0407" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0407"/>
        <description>Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization VirtualBox prior to 3.2.20, 4.0.22, 4.1.30, 4.2.20, and 4.3.4 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Core.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-17T08:31:03">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </submitted>
            <status_change date="2014-01-21T16:48:46.749-05:00">DRAFT</status_change>
            <status_change date="2014-02-10T04:00:22.299-05:00">INTERIM</status_change>
            <status_change date="2014-03-03T04:01:02.226-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="VirtualBox is installed" definition_ref="oval:org.mitre.oval:def:11581"/>
        <criterion comment="Check if Oracle VM VirtualBox is installed" test_ref="oval:org.mitre.oval:tst:42006"/>
        <criteria operator="OR" comment="Check versions of VirtualBox">
          <criteria operator="AND" comment="Affected versions of VirtualBox">
            <criterion comment="Check if Oracle VM VirtualBox version is greater than or equals to 3.2.0" test_ref="oval:org.mitre.oval:tst:88842"/>
            <criterion comment="Check if Oracle VM VirtualBox version is less than or equals to 3.2.18" test_ref="oval:org.mitre.oval:tst:100117"/>
          </criteria>
          <criteria operator="AND" comment="Affected versions of VirtualBox">
            <criterion comment="Check if Oracle VM VirtualBox version is greater than or equals to 4.0.0" test_ref="oval:org.mitre.oval:tst:88607"/>
            <criterion comment="Check if Oracle VM VirtualBox version is less than or equals to 4.0.20" test_ref="oval:org.mitre.oval:tst:100096"/>
          </criteria>
          <criteria operator="AND" comment="Affected versions of VirtualBox">
            <criterion comment="Check if Oracle VM VirtualBox version is greater than or equals to 4.1.0" test_ref="oval:org.mitre.oval:tst:88836"/>
            <criterion comment="Check if Oracle VM VirtualBox version is less than  or equals to 4.1.28" test_ref="oval:org.mitre.oval:tst:99957"/>
          </criteria>
          <criteria operator="AND" comment="Affected versions of VirtualBox">
            <criterion comment="Check if Oracle VM VirtualBox version is greater than or equals to 4.2.0" test_ref="oval:org.mitre.oval:tst:99857"/>
            <criterion comment="Check if Oracle VM VirtualBox version is less than  or equals to 4.2.18" test_ref="oval:org.mitre.oval:tst:99972"/>
          </criteria>
          <criteria operator="AND" comment="Affected versions of VirtualBox">
            <criterion comment="Check if Oracle VM VirtualBox version is greater than or equals to 4.3.0" test_ref="oval:org.mitre.oval:tst:100120"/>
            <criterion comment="Check if Oracle VM VirtualBox version is less than  or equals to 4.3.2" test_ref="oval:org.mitre.oval:tst:100166"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21831" version="5" class="vulnerability">
      <metadata>
        <title>Memory corruption vulnerability in Microsoft Internet Explorer (CVE-2014-0275) - MS14-010</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-0275" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0275"/>
        <description>Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-0285 and CVE-2014-0286.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-02-17T12:48:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-02-19T08:13:14.859-05:00">DRAFT</status_change>
            <status_change date="2014-03-10T04:00:35.412-04:00">INTERIM</status_change>
            <status_change date="2014-03-31T04:00:12.224-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:21831 - extended definitions of OS are without SP checks" date="2014-07-28T18:06:00.495-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T18:08:36.898-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:02:12.309-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="ie6">
          <criteria operator="OR" comment="xp/2003">
            <criteria operator="AND" comment="ie6/xp/version">
              <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
              <criterion comment="Check if the version of mshtml.dll is less than 6.0.2900.6498" test_ref="oval:org.mitre.oval:tst:100192"/>
            </criteria>
            <criteria operator="AND" comment="ie6/xp/2003/versions">
              <criteria operator="OR" comment="xp/2003">
                <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
                <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5281" test_ref="oval:org.mitre.oval:tst:100478"/>
            </criteria>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
        </criteria>
        <criteria operator="AND" comment="ie7">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="xp/2003/vista/2008/">
            <criteria operator="AND" comment="xp/2003/version">
              <criteria operator="OR" comment="either os">
                <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
                <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
                <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21366" test_ref="oval:org.mitre.oval:tst:100587"/>
            </criteria>
            <criteria operator="AND" comment="vista/2008/version">
              <criteria operator="OR" comment="either os">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="gdr/ldr">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.19016" test_ref="oval:org.mitre.oval:tst:100315"/>
                <criteria operator="AND" comment="ldr range">
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23303" test_ref="oval:org.mitre.oval:tst:100212"/>
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="ie8">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="vista/2008/win7/2008r2//versions">
            <criteria operator="AND" comment="vista/2008/versions">
              <criteria operator="OR" comment="either os">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="gdr/ldr">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19499" test_ref="oval:org.mitre.oval:tst:100606"/>
                <criteria operator="AND" comment="ldr range">
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23562" test_ref="oval:org.mitre.oval:tst:100657"/>
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="win7/2008 r2/version">
              <criteria operator="OR" comment="either os">
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="gdr/ldr">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18365" test_ref="oval:org.mitre.oval:tst:100432"/>
                <criteria operator="AND" comment="ldr range">
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22567" test_ref="oval:org.mitre.oval:tst:100439"/>
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="xp/2003/version">
              <criteria operator="OR" comment="either os">
                <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
                <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23562" test_ref="oval:org.mitre.oval:tst:100657"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="ie9">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16533" test_ref="oval:org.mitre.oval:tst:100604"/>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20644" test_ref="oval:org.mitre.oval:tst:100436"/>
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
            </criteria>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
        </criteria>
        <criteria operator="AND" comment="ie10">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16798" test_ref="oval:org.mitre.oval:tst:100469"/>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.20916" test_ref="oval:org.mitre.oval:tst:100274"/>
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.20000" test_ref="oval:org.mitre.oval:tst:80523"/>
            </criteria>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
        </criteria>
        <criteria operator="AND" comment="ie11">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16518" test_ref="oval:org.mitre.oval:tst:100481"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21700" version="3" class="vulnerability">
      <metadata>
        <title>Win32k Elevation of Privilege Vulnerability - CVE-2014-0300 (MS14-015)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-0300" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0300"/>
        <description>win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-03-13T14:34:18">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-03-14T11:06:08.188-04:00">DRAFT</status_change>
            <status_change date="2014-03-31T04:00:11.498-04:00">INTERIM</status_change>
            <status_change date="2014-04-21T04:00:20.887-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="XP (x86)+ vulnerable file version">
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <criterion comment="Check if the version of win32k.sys is less than 5.1.2600.6514" test_ref="oval:org.mitre.oval:tst:100494"/>
        </criteria>
        <criteria operator="AND" comment="XP X64/2K3(all) and vulnerable file version">
          <criteria operator="OR" comment="XP x64 / 2k3">
            <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
          </criteria>
          <criterion comment="Check if the version of win32k.sys is less than 5.2.3790.5296" test_ref="oval:org.mitre.oval:tst:100886"/>
        </criteria>
        <criteria operator="AND" comment="Vista / 2k8 + vulnerable file version">
          <criteria operator="OR" comment="Vista / 2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
            <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of win32k.sys is less than 6.0.6002.19036" test_ref="oval:org.mitre.oval:tst:100733"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:81723"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.0.6002.23325" test_ref="oval:org.mitre.oval:tst:100089"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / R2 + vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12292"/>
            <extend_definition comment="Microsoft Windows 7 x64 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12627"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12567"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12583"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.18388" test_ref="oval:org.mitre.oval:tst:100894"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:81763"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.22592" test_ref="oval:org.mitre.oval:tst:100902"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8/2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.16817" test_ref="oval:org.mitre.oval:tst:100579"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.2.9200.20000" test_ref="oval:org.mitre.oval:tst:80697"/>
              <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.20937" test_ref="oval:org.mitre.oval:tst:100323"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8.1 / 2K12 R2and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1 / 2k12 R2">
            <extend_definition comment="Microsoft Windows 8.1 (x86) is installed" definition_ref="oval:org.mitre.oval:def:20924"/>
            <extend_definition comment="Microsoft Windows 8.1 (x64) is installed" definition_ref="oval:org.mitre.oval:def:20956"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of win32k.sys is less than 6.3.9600.16650" test_ref="oval:org.mitre.oval:tst:100702"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20956" version="3" class="inventory">
      <metadata>
        <title>Microsoft Windows 8.1 (x64) is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 8.1</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/o:microsoft:windows_8:1::x64"/>
        <description>The operating system installed on the system is Microsoft Windows 8.1 x64</description>
        <oval_repository>
          <dates>
            <submitted date="2013-10-24T16:31:26.748+04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </submitted>
            <status_change date="2013-12-12T09:53:59.952-05:00">DRAFT</status_change>
            <status_change date="2013-12-30T04:01:01.069-05:00">INTERIM</status_change>
            <status_change date="2014-01-20T04:01:16.975-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Microsoft Windows 8.1 is installed" definition_ref="oval:org.mitre.oval:def:18863"/>
        <criterion comment="a version of Windows for the x64 architecture is installed" test_ref="oval:org.mitre.oval:tst:3653"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20924" version="3" class="inventory">
      <metadata>
        <title>Microsoft Windows 8.1 (x86) is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 8.1</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/o:microsoft:windows_8:1::x86"/>
        <description>The operating system installed on the system is Microsoft Windows 8.1 x86</description>
        <oval_repository>
          <dates>
            <submitted date="2013-10-24T16:31:26.748+04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </submitted>
            <status_change date="2013-12-12T09:54:00.199-05:00">DRAFT</status_change>
            <status_change date="2013-12-30T04:01:00.134-05:00">INTERIM</status_change>
            <status_change date="2014-01-20T04:01:15.934-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Microsoft Windows 8.1 is installed" definition_ref="oval:org.mitre.oval:def:18863"/>
        <criterion comment="a version of Windows for the x86 architecture is installed" test_ref="oval:org.mitre.oval:tst:3823"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21562" version="5" class="vulnerability">
      <metadata>
        <title>TCP/IP version 6 (IPv6) denial of service vulnerability (CVE-2014-0254) - MS14-006</title>
        <affected family="windows">
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-0254" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0254"/>
        <description>The IPv6 implementation in Microsoft Windows 8, Windows Server 2012, and Windows RT does not properly validate packets, which allows remote attackers to cause a denial of service (system hang) via crafted ICMPv6 Router Advertisement packets, aka "TCP/IP Version 6 (IPv6) Denial of Service Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-02-14T16:35:10">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-02-14T13:02:24.800-05:00">DRAFT</status_change>
            <status_change date="2014-03-03T04:01:01.692-05:00">INTERIM</status_change>
            <status_change date="2014-03-24T04:01:31.185-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="Win 8 32/64 bit or Server 2012 64 bit">
          <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
          <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
          <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
        </criteria>
        <criteria operator="OR" comment="Check for vulnerable version">
          <criterion comment="Check if the version of tcpip.sys is less than 6.2.9200.16754" test_ref="oval:org.mitre.oval:tst:100239"/>
          <criteria operator="AND" comment="Check for LDR">
            <criterion comment="Check if the version of tcpip.sys is greater than or equal to 6.2.9200.20000" test_ref="oval:org.mitre.oval:tst:80315"/>
            <criterion comment="Check if the version of tcpip.sys is less than 6.2.9200.20867" test_ref="oval:org.mitre.oval:tst:100355"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21438" version="3" class="vulnerability">
      <metadata>
        <title>Unspecified vulnerability in the VirtualBox component in Oracle Virtualization VirtualBox 3.2.20, 4.0.22, 4.1.30, 4.2.20, and 4.3.4 allows local users to affect confidentiality, integrity, and availability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>VirtualBox</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2014-0405" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0405"/>
        <description>Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization VirtualBox prior to 3.2.20, 4.0.22, 4.1.30, 4.2.20, and 4.3.4 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Core.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-17T08:31:03">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </submitted>
            <status_change date="2014-01-21T16:48:46.316-05:00">DRAFT</status_change>
            <status_change date="2014-02-10T04:00:21.478-05:00">INTERIM</status_change>
            <status_change date="2014-03-03T04:01:00.562-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="VirtualBox is installed" definition_ref="oval:org.mitre.oval:def:11581"/>
        <criterion comment="Check if Oracle VM VirtualBox is installed" test_ref="oval:org.mitre.oval:tst:42006"/>
        <criteria operator="OR" comment="Check versions of VirtualBox">
          <criteria operator="AND" comment="Affected versions of VirtualBox">
            <criterion comment="Check if Oracle VM VirtualBox version is greater than or equals to 3.2.0" test_ref="oval:org.mitre.oval:tst:88842"/>
            <criterion comment="Check if Oracle VM VirtualBox version is less than or equals to 3.2.18" test_ref="oval:org.mitre.oval:tst:100117"/>
          </criteria>
          <criteria operator="AND" comment="Affected versions of VirtualBox">
            <criterion comment="Check if Oracle VM VirtualBox version is greater than or equals to 4.0.0" test_ref="oval:org.mitre.oval:tst:88607"/>
            <criterion comment="Check if Oracle VM VirtualBox version is less than or equals to 4.0.20" test_ref="oval:org.mitre.oval:tst:100096"/>
          </criteria>
          <criteria operator="AND" comment="Affected versions of VirtualBox">
            <criterion comment="Check if Oracle VM VirtualBox version is greater than or equals to 4.1.0" test_ref="oval:org.mitre.oval:tst:88836"/>
            <criterion comment="Check if Oracle VM VirtualBox version is less than  or equals to 4.1.28" test_ref="oval:org.mitre.oval:tst:99957"/>
          </criteria>
          <criteria operator="AND" comment="Affected versions of VirtualBox">
            <criterion comment="Check if Oracle VM VirtualBox version is greater than or equals to 4.2.0" test_ref="oval:org.mitre.oval:tst:99857"/>
            <criterion comment="Check if Oracle VM VirtualBox version is less than  or equals to 4.2.18" test_ref="oval:org.mitre.oval:tst:99972"/>
          </criteria>
          <criteria operator="AND" comment="Affected versions of VirtualBox">
            <criterion comment="Check if Oracle VM VirtualBox version is greater than or equals to 4.3.0" test_ref="oval:org.mitre.oval:tst:100120"/>
            <criterion comment="Check if Oracle VM VirtualBox version is less than  or equals to 4.3.2" test_ref="oval:org.mitre.oval:tst:100166"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11581" version="9" class="inventory">
      <metadata>
        <title>VirtualBox is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>VirtualBox</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:oracle:xvm_virtualbox"/>
        <description>VirtualBox is installed</description>
        <oval_repository>
          <dates>
            <submitted date="2010-12-17T19:26:32">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-12-21T11:27:26.795-05:00">DRAFT</status_change>
            <status_change date="2011-01-10T04:00:04.930-05:00">INTERIM</status_change>
            <status_change date="2011-01-31T04:00:03.574-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11581 - Modified inventory definition CPE IDs to match the CPE IDs found in the official CPE dictionary" date="2011-03-29T13:53:00.154-04:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </modified>
            <status_change date="2011-03-29T13:54:37.133-04:00">INTERIM</status_change>
            <status_change date="2011-04-18T04:00:03.500-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11581 - Found a few issues with the current inventory definition for VirtualBox and the vulnerability definition which uses it, and the fixes plus a bit more are attached. The core issue is that the registry key where the relevant information is stored has had 4 different values since version 3.0.0, with the most recent change causing the vulnerability definition to throw an error." date="2011-10-17T13:02:00.116-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-10-17T13:24:26.817-04:00">INTERIM</status_change>
            <status_change date="2011-11-07T04:00:09.278-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:15297 - modificated vulnerabilities for VirtualBox" date="2013-12-05T10:43:00.197-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-12-05T10:45:12.057-05:00">INTERIM</status_change>
            <status_change date="2013-12-23T04:00:06.821-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criterion comment="Check if Sun xVM VirtualBox is installed" test_ref="oval:org.mitre.oval:tst:41938"/>
        <criterion comment="Check if Sun VirtualBox is installed" test_ref="oval:org.mitre.oval:tst:44050"/>
        <criterion comment="Check if Oracle VM VirtualBox is installed" test_ref="oval:org.mitre.oval:tst:42006"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21033" version="5" class="vulnerability">
      <metadata>
        <title>Port-Class Driver Double Fetch Vulnerability (CVE-2013-3907) - MS13-101</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Vista</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2013-3907" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3907"/>
        <description>portcls.sys in the kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT allows local users to gain privileges via a crafted application, aka "Port-Class Driver Double Fetch Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2013-12-13T16:20:58">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-12-16T12:25:06.071-05:00">DRAFT</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:21033 - corrected portcls.sys version on Windows 7 in accordance with MSKB-2887069" date="2013-12-17T14:39:00.500-05:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2014-01-06T04:00:47.244-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:1504 - The sign \ was removed before the sign _." date="2014-01-14T16:04:00.629-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2014-02-03T04:01:27.587-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="vista/2008/version">
          <criteria operator="OR" comment="vista/2008">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
            <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of portcls.sys is less than 6.0.6002.18974" test_ref="oval:org.mitre.oval:tst:89922"/>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of portcls.sys is less than 6.0.6002.23261" test_ref="oval:org.mitre.oval:tst:89928"/>
              <criterion comment="Check if the version of portcls.sys is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:89957"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="win 7/2008 r2/versions">
          <criteria operator="OR" comment="win/2008 r2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12292"/>
            <extend_definition comment="Microsoft Windows 7 x64 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12627"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12567"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12583"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of portcls.sys is less than 6.1.7601.18276" test_ref="oval:org.mitre.oval:tst:89911"/>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of portcls.sys is less than 6.1.7601.22472" test_ref="oval:org.mitre.oval:tst:89934"/>
              <criterion comment="Check if the version of portcls.sys is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:89933"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="win 8/server 2012">
          <criteria operator="OR" comment="win 8/server 2012">
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of portcls.sys is less than 6.2.9200.16726" test_ref="oval:org.mitre.oval:tst:90097"/>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of portcls.sys is greater than or equal to 6.2.9200.20000" test_ref="oval:org.mitre.oval:tst:89958"/>
              <criterion comment="Check if the version of portcls.sys is less than 6.2.9200.20836" test_ref="oval:org.mitre.oval:tst:89849"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21026" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability (CVE-2013-5048) - MS13-097</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2013-5048" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5048"/>
        <description>Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-5047.</description>
        <oval_repository>
          <dates>
            <submitted date="2013-12-13T09:16:27">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-12-16T12:20:50.582-05:00">DRAFT</status_change>
            <status_change date="2014-01-06T04:00:46.881-05:00">INTERIM</status_change>
            <status_change date="2014-01-27T04:00:55.044-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:21026 - extended definitions of OS are without SP checks" date="2014-07-28T18:04:00.247-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T18:06:32.912-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:02:10.603-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 and vulnerable file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="XP / 2k3 and vulnerable file versions">
            <criteria operator="AND" comment="XP (32 bit) and vulnerable file version">
              <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
              <criterion comment="Check if the version of mshtml.dll is less than 6.0.2900.6470" test_ref="oval:org.mitre.oval:tst:90080"/>
            </criteria>
            <criteria operator="AND" comment="2k3 /XP x64 and vulnerable file version">
              <criteria operator="OR" comment="2k3 /XP x64">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
                <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5246" test_ref="oval:org.mitre.oval:tst:89524"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 7 and vulnerable file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="XP / 2k3 / Vista / 2k8 and vulnerable file versions">
            <criteria operator="AND" comment="XP / 2K3 and vulnerable file version">
              <criteria operator="OR" comment="XP / 2K3">
                <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
                <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21364" test_ref="oval:org.mitre.oval:tst:90034"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista / 2K8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23258" test_ref="oval:org.mitre.oval:tst:90042"/>
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                </criteria>
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.18972" test_ref="oval:org.mitre.oval:tst:89809"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 and vulnerable file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="XP / 2k3 / Vista / 2k8 / Win 7 / R2 and vulnerable file versions">
            <criteria operator="AND" comment="XP / 2K3 and vulnerable file version">
              <criteria operator="OR" comment="XP / 2K3">
                <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
                <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23543" test_ref="oval:org.mitre.oval:tst:90036"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista / 2K8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23543" test_ref="oval:org.mitre.oval:tst:90036"/>
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                </criteria>
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19489" test_ref="oval:org.mitre.oval:tst:89244"/>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file version">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22500" test_ref="oval:org.mitre.oval:tst:89821"/>
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                </criteria>
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18305" test_ref="oval:org.mitre.oval:tst:89826"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 and vulnerable file version">
          <criteria operator="OR" comment="Vista / 2K8 / Win 7 / R2 and vulnerable file version">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20637" test_ref="oval:org.mitre.oval:tst:90004"/>
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
            </criteria>
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16526" test_ref="oval:org.mitre.oval:tst:90046"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
        </criteria>
        <criteria operator="AND" comment="IE 10 and vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2 / Win 8 / 2k12 and vulnerable file version">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.20861" test_ref="oval:org.mitre.oval:tst:89912"/>
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.20000" test_ref="oval:org.mitre.oval:tst:80523"/>
            </criteria>
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16750" test_ref="oval:org.mitre.oval:tst:89529"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
        </criteria>
        <criteria operator="AND" comment="IE 11 and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1 / 2k12 R2 and vulnerable file version">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 is installed" definition_ref="oval:org.mitre.oval:def:18863"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16476" test_ref="oval:org.mitre.oval:tst:90069"/>
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20974" version="3" class="vulnerability">
      <metadata>
        <title>Win32k Integer Overflow Vulnerability (CVE-2013-5058) - MS13-101</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2013-5058" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5058"/>
        <description>Integer overflow in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 allows local users to gain privileges via a crafted application, aka "Win32k Integer Overflow Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2013-12-13T16:20:58">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-12-16T12:25:07.792-05:00">DRAFT</status_change>
            <status_change date="2014-01-06T04:00:46.592-05:00">INTERIM</status_change>
            <status_change date="2014-01-27T04:00:49.845-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="xp sp3/version">
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <criterion comment="Check if the version of win32k.sys is less than 5.1.2600.6473" test_ref="oval:org.mitre.oval:tst:90070"/>
        </criteria>
        <criteria operator="AND" comment="win xp/server 2003/versions">
          <criteria operator="OR" comment="xp/server 2003">
            <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
          </criteria>
          <criterion comment="Check if the version of win32k.sys is less than 5.2.3790.5250" test_ref="oval:org.mitre.oval:tst:89547"/>
        </criteria>
        <criteria operator="AND" comment="vista/2008/version">
          <criteria operator="OR" comment="vista/2008">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
            <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.0.6002.18974" test_ref="oval:org.mitre.oval:tst:89723"/>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of win32k.sys is less than 6.0.6002.23261" test_ref="oval:org.mitre.oval:tst:89993"/>
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:81723"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="win 7/2008 r2/versions">
          <criteria operator="OR" comment="win/2008 r2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12292"/>
            <extend_definition comment="Microsoft Windows 7 x64 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12627"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12567"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12583"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.18300" test_ref="oval:org.mitre.oval:tst:89944"/>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.22496" test_ref="oval:org.mitre.oval:tst:89852"/>
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:81763"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="win 8/server 2012">
          <criteria operator="OR" comment="win 8/server 2012">
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.16758" test_ref="oval:org.mitre.oval:tst:90087"/>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.20871" test_ref="oval:org.mitre.oval:tst:89113"/>
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.2.9200.20000" test_ref="oval:org.mitre.oval:tst:80697"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="win 8.1/2012 R2">
          <criteria operator="OR" comment="8.1/ 2012 R2">
            <extend_definition comment="Microsoft Windows 8.1 is installed" definition_ref="oval:org.mitre.oval:def:18863"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of win32k.sys is less than 6.3.9600.16457" test_ref="oval:org.mitre.oval:tst:89453"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20965" version="3" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability - CVE-2013-3846 (MS13-055)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Vista</platform>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2013-3846" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3846"/>
        <description>Use-after-free vulnerability in Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted CSpliceTreeEngine::InsertSplice object in an HTML document, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3143 and CVE-2013-3161.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-03T17:53:56">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2014-01-03T11:46:18.864-05:00">DRAFT</status_change>
            <status_change date="2014-01-20T04:01:17.499-05:00">INTERIM</status_change>
            <status_change date="2014-02-10T04:00:20.168-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 9 + Win 7/2K8 R2/Vista/2K8 + vulnerable file versions">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="Either OS">
            <extend_definition comment="Microsoft Windows 7 (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12292"/>
            <extend_definition comment="Microsoft Windows 7 x64 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12627"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12567"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
          </criteria>
          <criteria operator="OR" comment="Either Version">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16496" test_ref="oval:org.mitre.oval:tst:81875"/>
            <criteria operator="AND" comment="Check for LDR range">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20606" test_ref="oval:org.mitre.oval:tst:81808"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + Win 7/2K8 R2/Win8/2k12 + vulnerable file versions">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Either OS">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12292"/>
            <extend_definition comment="Microsoft Windows 7 x64 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12627"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12567"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Either Version">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16635" test_ref="oval:org.mitre.oval:tst:81840"/>
            <criteria operator="AND" comment="Check for LDR range">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.20000" test_ref="oval:org.mitre.oval:tst:80523"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.20742" test_ref="oval:org.mitre.oval:tst:81835"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20872" version="4" class="vulnerability">
      <metadata>
        <title>WinVerifyTrust Signature Validation Vulnerability (CVE-2013-3900) - MS13-098</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2013-3900" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3900"/>
        <description>The WinVerifyTrust function in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 does not properly validate PE file digests during Authenticode signature verification, which allows remote attackers to execute arbitrary code via a crafted PE file, aka "WinVerifyTrust Signature Validation Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2013-12-13T08:15:54">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-12-16T12:19:08.816-05:00">DRAFT</status_change>
            <status_change date="2014-01-06T04:00:45.856-05:00">INTERIM</status_change>
            <status_change date="2014-01-06T04:00:31.791-05:00">INTERIM</status_change>
            <status_change date="2014-01-27T04:00:38.866-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Microsoft Windows XP x86 and vulnerable file version">
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <criterion comment="Check if the version of Imagehlp.dll is less than 5.1.2600.6479" test_ref="oval:org.mitre.oval:tst:90009"/>
        </criteria>
        <criteria operator="AND" comment="Microsoft Windows 2003/XP x64 and vulnerable file version">
          <criteria operator="OR" comment="Microsoft Windows 2003/XP x64">
            <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
          </criteria>
          <criterion comment="Check if the version of Imagehlp.dll is less than 5.2.3790.5240" test_ref="oval:org.mitre.oval:tst:89829"/>
        </criteria>
        <criteria operator="AND" comment="Microsoft Windows Vista/2008 and vulnerable file version">
          <criteria operator="OR" comment="Microsoft Windows Vista/2008">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
            <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
          </criteria>
          <criteria operator="OR" comment="vulnerable file version">
            <criterion comment="Check if the version of Imagehlp.dll is less than 6.0.6002.18971" test_ref="oval:org.mitre.oval:tst:89832"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Imagehlp.dll is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:89925"/>
              <criterion comment="Check if the version of Imagehlp.dll is less than 6.0.6002.23248" test_ref="oval:org.mitre.oval:tst:90024"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Microsoft Windows 7/2008 R2 SP1 and vulnerable file version">
          <criteria operator="OR" comment="Microsoft Windows 7/R2 SP1">
            <extend_definition comment="Microsoft Windows 7 (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12292"/>
            <extend_definition comment="Microsoft Windows 7 x64 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12627"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12567"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12583"/>
          </criteria>
          <criteria operator="OR" comment="vulnerable file version">
            <criterion comment="Check if the version of Imagehlp.dll is less than 6.1.7601.18288" test_ref="oval:org.mitre.oval:tst:89921"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Imagehlp.dll is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:89106"/>
              <criterion comment="Check if the version of Imagehlp.dll is less than 6.1.7601.22484" test_ref="oval:org.mitre.oval:tst:90102"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Microsoft Windows 8/2012 and vulnerable file version">
          <criteria operator="OR" comment="Microsoft Windows 8/2012">
            <extend_definition comment="Microsoft Windows 8 is installed" definition_ref="oval:org.mitre.oval:def:15732"/>
            <extend_definition comment="Microsoft Windows Server 2012 is installed" definition_ref="oval:org.mitre.oval:def:16359"/>
          </criteria>
          <criteria operator="OR" comment="vulnerable file version">
            <criterion comment="Check if the version of Imagehlp.dll is less than 6.2.9200.16745" test_ref="oval:org.mitre.oval:tst:90022"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Imagehlp.dll is greater than or equal to 6.2.9200.20000" test_ref="oval:org.mitre.oval:tst:90089"/>
              <criterion comment="Check if the version of Imagehlp.dll is less than 6.2.9200.20856" test_ref="oval:org.mitre.oval:tst:89256"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Microsoft Windows 8/2012 and vulnerable file version">
          <criteria operator="OR" comment="Microsoft Windows 8.1/2012 R2">
            <extend_definition comment="Microsoft Windows 8.1 is installed" definition_ref="oval:org.mitre.oval:def:18863"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of Imagehlp.dll is less than 6.3.9600.16438" test_ref="oval:org.mitre.oval:tst:89904"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20829" version="4" class="vulnerability">
      <metadata>
        <title>TrueType Font Parsing Vulnerability (CVE-2013-3903) - MS13-101</title>
        <affected family="windows">
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2013-3903" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3903"/>
        <description>Array index error in win32k.sys in the kernel-mode drivers in Microsoft Windows 8, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to cause a denial of service (reboot) via a crafted TrueType font (TTF) file, aka "TrueType Font Parsing Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2013-12-13T16:20:58">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-12-16T12:25:08.966-05:00">DRAFT</status_change>
            <status_change date="2014-01-06T04:00:45.561-05:00">INTERIM</status_change>
            <status_change date="2014-01-06T04:00:31.551-05:00">INTERIM</status_change>
            <status_change date="2014-01-27T04:00:35.360-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="win 8/server 2012">
          <criteria operator="OR" comment="win 8/server 2012">
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.16758" test_ref="oval:org.mitre.oval:tst:90087"/>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.20871" test_ref="oval:org.mitre.oval:tst:89113"/>
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.2.9200.20000" test_ref="oval:org.mitre.oval:tst:80697"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="win 2012 R2">
          <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          <criterion comment="Check if the version of win32k.sys is less than 6.3.9600.16457" test_ref="oval:org.mitre.oval:tst:89453"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20798" version="5" class="vulnerability">
      <metadata>
        <title>SignalR XSS Vulnerability (CVE-2013-5042) - MS13-103</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Visual Studio Team Foundation Server</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2013-5042" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5042"/>
        <description>Cross-site scripting (XSS) vulnerability in Microsoft ASP.NET SignalR 1.1.x before 1.1.4 and 2.0.x before 2.0.1, and Visual Studio Team Foundation Server 2013, allows remote attackers to inject arbitrary web script or HTML via crafted Forever Frame transport protocol data, aka "SignalR XSS Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2013-12-13T19:38:53">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-12-16T12:27:45.400-05:00">DRAFT</status_change>
            <status_change date="2014-01-06T04:00:45.490-05:00">INTERIM</status_change>
            <status_change date="2014-01-06T04:00:31.500-05:00">INTERIM</status_change>
            <status_change date="2014-01-27T04:00:31.970-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Microsoft Visual Studio Team Foundation Server 2013 is installed" definition_ref="oval:org.mitre.oval:def:20854"/>
        <criterion comment="Check if the version of Microsoft.AspNet.SignalR.Core.dll is less than 1.1.21022.0" test_ref="oval:org.mitre.oval:tst:89989"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20854" version="4" class="inventory">
      <metadata>
        <title>Microsoft Visual Studio Team Foundation Server 2013 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <product>Microsoft Visual Studio Team Foundation Server</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:visual_studio_team_foundation_server:2013"/>
        <description>Microsoft Visual Studio Team Foundation Server 2013 is installed</description>
        <oval_repository>
          <dates>
            <submitted date="2013-12-13T19:38:53">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-12-16T12:27:45.255-05:00">DRAFT</status_change>
            <status_change date="2014-01-06T04:00:45.786-05:00">INTERIM</status_change>
            <status_change date="2014-01-06T04:00:31.721-05:00">INTERIM</status_change>
            <status_change date="2014-01-27T04:00:37.681-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="Check if Visual Studio Team Foundation Server is installed" test_ref="oval:org.mitre.oval:tst:90023"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20779" version="6" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability (CVE-2013-5051) - MS13-097</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2013-5051" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5051"/>
        <description>Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2013-12-13T09:16:27">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-12-16T12:20:58.302-05:00">DRAFT</status_change>
            <status_change date="2014-01-06T04:00:45.391-05:00">INTERIM</status_change>
            <status_change date="2014-01-06T04:00:31.427-05:00">INTERIM</status_change>
            <status_change date="2014-01-27T04:00:31.013-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:20779 - extended definitions of OS are without SP checks" date="2014-07-28T18:04:00.247-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T18:06:29.202-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:02:10.357-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 10 and vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2 / Win 8 / 2k12 and vulnerable file version">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.20861" test_ref="oval:org.mitre.oval:tst:89912"/>
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.20000" test_ref="oval:org.mitre.oval:tst:80523"/>
            </criteria>
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16750" test_ref="oval:org.mitre.oval:tst:89529"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
        </criteria>
        <criteria operator="AND" comment="IE 11 and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1 / 2k12 R2 and vulnerable file version">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 is installed" definition_ref="oval:org.mitre.oval:def:18863"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16476" test_ref="oval:org.mitre.oval:tst:90069"/>
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20776" version="6" class="vulnerability">
      <metadata>
        <title>Internet Explorer Elevation of Privilege Vulnerability (CVE-2013-5046) - MS13-097</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2013-5046" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5046"/>
        <description>Microsoft Internet Explorer 7 through 11 allows local users to bypass the Protected Mode protection mechanism, and consequently gain privileges, by leveraging the ability to execute sandboxed code, aka "Internet Explorer Elevation of Privilege Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2013-12-13T09:16:27">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-12-16T12:21:00.325-05:00">DRAFT</status_change>
            <status_change date="2014-01-06T04:00:45.157-05:00">INTERIM</status_change>
            <status_change date="2014-01-06T04:00:31.285-05:00">INTERIM</status_change>
            <status_change date="2014-01-27T04:00:30.506-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:20776 - extended definitions of OS are without SP checks" date="2014-07-28T18:04:00.247-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T18:06:32.607-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:02:09.968-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 7 and vulnerable file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="XP / 2k3 / Vista / 2k8 and vulnerable file versions">
            <criteria operator="AND" comment="XP / 2K3 and vulnerable file version">
              <criteria operator="OR" comment="XP / 2K3">
                <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
                <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21364" test_ref="oval:org.mitre.oval:tst:90034"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista / 2K8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23258" test_ref="oval:org.mitre.oval:tst:90042"/>
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                </criteria>
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.18972" test_ref="oval:org.mitre.oval:tst:89809"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 and vulnerable file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="XP / 2k3 / Vista / 2k8 / Win 7 / R2 and vulnerable file versions">
            <criteria operator="AND" comment="XP / 2K3 and vulnerable file version">
              <criteria operator="OR" comment="XP / 2K3">
                <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
                <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23543" test_ref="oval:org.mitre.oval:tst:90036"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista / 2K8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23543" test_ref="oval:org.mitre.oval:tst:90036"/>
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                </criteria>
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19489" test_ref="oval:org.mitre.oval:tst:89244"/>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file version">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22500" test_ref="oval:org.mitre.oval:tst:89821"/>
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                </criteria>
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18305" test_ref="oval:org.mitre.oval:tst:89826"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 and vulnerable file version">
          <criteria operator="OR" comment="Vista / 2K8 / Win 7 / R2 and vulnerable file version">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20637" test_ref="oval:org.mitre.oval:tst:90004"/>
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
            </criteria>
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16526" test_ref="oval:org.mitre.oval:tst:90046"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
        </criteria>
        <criteria operator="AND" comment="IE 10 and vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2 / Win 8 / 2k12 and vulnerable file version">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.20861" test_ref="oval:org.mitre.oval:tst:89912"/>
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.20000" test_ref="oval:org.mitre.oval:tst:80523"/>
            </criteria>
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16750" test_ref="oval:org.mitre.oval:tst:89529"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
        </criteria>
        <criteria operator="AND" comment="IE 11 and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1 / 2k12 R2 and vulnerable file version">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 is installed" definition_ref="oval:org.mitre.oval:def:18863"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16476" test_ref="oval:org.mitre.oval:tst:90069"/>
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20760" version="4" class="vulnerability">
      <metadata>
        <title>Use-After-Free Vulnerability in Microsoft Scripting Runtime Object Library (CVE-2013-5056) - MS13-099</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2013-5056" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5056"/>
        <description>Use-after-free vulnerability in the Scripting Runtime Object Library in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site that is visited with Internet Explorer, aka "Use-After-Free Vulnerability in Microsoft Scripting Runtime Object Library."</description>
        <oval_repository>
          <dates>
            <submitted date="2013-12-13T13:04:03">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-12-16T12:22:19.873-05:00">DRAFT</status_change>
            <status_change date="2014-01-06T04:00:44.823-05:00">INTERIM</status_change>
            <status_change date="2014-01-06T04:00:31.094-05:00">INTERIM</status_change>
            <status_change date="2014-01-27T04:00:28.176-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Check for vulnerable Windows XP SP3(x86) and scrrun.dll version">
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <criterion comment="Check if version of Scrrun.dll version is greater than or equal to 5.7.0.0" test_ref="oval:org.mitre.oval:tst:89920"/>
          <criterion comment="Check if version of Scrrun.dll version is less than 5.7.6002.18960" test_ref="oval:org.mitre.oval:tst:89894"/>
        </criteria>
        <criteria operator="AND" comment="Check for vulnerable Windows 2003 SP2(x86)/(x64)/(ia-64)/XP SP2(x64) and scrrun.dll version">
          <criteria operator="OR" comment="Check for vulnerable Windows 2003 SP2(x86)/(x64)/(ia-64)/XP SP2(x64)">
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
            <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
          </criteria>
          <criteria operator="OR" comment="Check Scrrun.dll version w.r.t Windows Script 5.7 Windows Script 5.6">
            <criteria operator="AND" comment="Check Scrrun.dll version w.r.t Windows Script 5.7">
              <criterion comment="Check if version of Scrrun.dll version is greater than or equal to 5.7.0.0" test_ref="oval:org.mitre.oval:tst:89920"/>
              <criterion comment="Check if version of Scrrun.dll version is less than 5.7.6002.18960" test_ref="oval:org.mitre.oval:tst:89894"/>
            </criteria>
            <criterion comment="Check if version of Scrrun.dll version is less than 5.6.0.8851" test_ref="oval:org.mitre.oval:tst:89464"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Check for Vulnerable Windows Vista SP2(x86)/(x64)/Server 2008 SP2(x86)/(x64)/(ia-64) and scrrun.dll version">
          <criteria operator="OR" comment="Check for Vulnerable Windows Vista SP2(x86)/(x64)/Server 2008 SP2(x86)/(x64)/(ia-64)">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
            <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
          </criteria>
          <criteria operator="OR" comment="Check for LDR/GDR">
            <criterion comment="Check if version of Scrrun.dll version is less than 5.7.6002.18960" test_ref="oval:org.mitre.oval:tst:90001"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if version of Scrrun.dll is greater than or equal to 5.7.6002.23000" test_ref="oval:org.mitre.oval:tst:89971"/>
              <criterion comment="Check if version of Scrrun.dll is less than 5.7.6002.23242" test_ref="oval:org.mitre.oval:tst:90081"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Check for Vulnerable Windows 7 SP1(x86)/(x64)/Server 2008 R2 SP1(x64)/(ia-64) and scrrun.dll version">
          <criteria operator="OR" comment="Check for Vulnerable Windows 7 SP1(x86)/(x64)/Server 2008 R2 SP1(x64)/(ia-64)">
            <extend_definition comment="Microsoft Windows 7 (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12292"/>
            <extend_definition comment="Microsoft Windows 7 x64 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12627"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12567"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12583"/>
          </criteria>
          <criteria operator="OR" comment="Check for LDR/GDR">
            <criterion comment="Check if version of Scrrun.dll version is less than 5.8.7601.18283" test_ref="oval:org.mitre.oval:tst:89457"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if version of Scrrun.dll is greater than or equal to 5.8.7601.22000" test_ref="oval:org.mitre.oval:tst:89846"/>
              <criterion comment="Check if version of Scrrun.dll is less than 5.8.7601.22480" test_ref="oval:org.mitre.oval:tst:90083"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Check for Vulnerable Windows 8(x86)/(x64)/Server 2012 and scrrun.dll version">
          <criteria operator="OR" comment="Check for Vulnerable Windows 8(x86)/(x64)/Server 2012">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for LDR/GDR">
            <criterion comment="Check if version of Scrrun.dll version is less than 5.8.9200.16734" test_ref="oval:org.mitre.oval:tst:89793"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if version of Scrrun.dll is greater than or equal to 5.8.9200.20000" test_ref="oval:org.mitre.oval:tst:89537"/>
              <criterion comment="Check if version of Scrrun.dll is less than 5.8.9200.20845" test_ref="oval:org.mitre.oval:tst:89770"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Check for Vulnerable Windows 8.1(x86)/(x64)/Server 2012 R2 and scrrun.dll version">
          <criteria operator="OR" comment="Check for Vulnerable Windows 8.1(x86)/(x64)/Server 2012 R2">
            <extend_definition comment="Microsoft Windows 8.1 is installed" definition_ref="oval:org.mitre.oval:def:18863"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if version of Scrrun.dll version is less than 5.8.9600.16429" test_ref="oval:org.mitre.oval:tst:89954"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20614" version="6" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability (CVE-2013-5047) - MS13-097</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2013-5047" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5047"/>
        <description>Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-5048.</description>
        <oval_repository>
          <dates>
            <submitted date="2013-12-13T09:16:27">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-12-16T12:20:53.050-05:00">DRAFT</status_change>
            <status_change date="2014-01-06T04:00:44.402-05:00">INTERIM</status_change>
            <status_change date="2014-01-06T04:00:30.859-05:00">INTERIM</status_change>
            <status_change date="2014-01-27T04:00:18.479-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:20614 - extended definitions of OS are without SP checks" date="2014-07-28T18:04:00.247-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T18:06:31.469-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:02:08.916-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 and vulnerable file version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="XP / 2k3 and vulnerable file versions">
            <criteria operator="AND" comment="XP (32 bit) and vulnerable file version">
              <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
              <criterion comment="Check if the version of mshtml.dll is less than 6.0.2900.6470" test_ref="oval:org.mitre.oval:tst:90080"/>
            </criteria>
            <criteria operator="AND" comment="2k3 /XP x64 and vulnerable file version">
              <criteria operator="OR" comment="2k3 /XP x64">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
                <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5246" test_ref="oval:org.mitre.oval:tst:89524"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 7 and vulnerable file version">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="XP / 2k3 / Vista / 2k8 and vulnerable file versions">
            <criteria operator="AND" comment="XP / 2K3 and vulnerable file version">
              <criteria operator="OR" comment="XP / 2K3">
                <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
                <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21364" test_ref="oval:org.mitre.oval:tst:90034"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista / 2K8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23258" test_ref="oval:org.mitre.oval:tst:90042"/>
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                </criteria>
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.18972" test_ref="oval:org.mitre.oval:tst:89809"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 and vulnerable file version">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="XP / 2k3 / Vista / 2k8 / Win 7 / R2 and vulnerable file versions">
            <criteria operator="AND" comment="XP / 2K3 and vulnerable file version">
              <criteria operator="OR" comment="XP / 2K3">
                <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
                <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23543" test_ref="oval:org.mitre.oval:tst:90036"/>
            </criteria>
            <criteria operator="AND" comment="Vista / 2k8 and vulnerable file version">
              <criteria operator="OR" comment="Vista / 2K8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23543" test_ref="oval:org.mitre.oval:tst:90036"/>
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                </criteria>
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19489" test_ref="oval:org.mitre.oval:tst:89244"/>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file version">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22500" test_ref="oval:org.mitre.oval:tst:89821"/>
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                </criteria>
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18305" test_ref="oval:org.mitre.oval:tst:89826"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 and vulnerable file version">
          <criteria operator="OR" comment="Vista / 2K8 / Win 7 / R2 and vulnerable file version">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20637" test_ref="oval:org.mitre.oval:tst:90004"/>
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
            </criteria>
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16526" test_ref="oval:org.mitre.oval:tst:90046"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
        </criteria>
        <criteria operator="AND" comment="IE 10 and vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2 / Win 8 / 2k12 and vulnerable file version">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.20861" test_ref="oval:org.mitre.oval:tst:89912"/>
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.20000" test_ref="oval:org.mitre.oval:tst:80523"/>
            </criteria>
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16750" test_ref="oval:org.mitre.oval:tst:89529"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
        </criteria>
        <criteria operator="AND" comment="IE 11 and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1 / 2k12 R2 and vulnerable file version">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 is installed" definition_ref="oval:org.mitre.oval:def:18863"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16476" test_ref="oval:org.mitre.oval:tst:90069"/>
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20216" version="6" class="vulnerability">
      <metadata>
        <title>Internet Explorer Elevation of Privilege Vulnerability (CVE-2013-5045) - MS13-097</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2013-5045" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5045"/>
        <description>Microsoft Internet Explorer 10 and 11 allows local users to bypass the Protected Mode protection mechanism, and consequently gain privileges, by leveraging the ability to execute sandboxed code, aka "Internet Explorer Elevation of Privilege Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2013-12-13T09:16:27">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-12-16T12:20:48.370-05:00">DRAFT</status_change>
            <status_change date="2014-01-06T04:00:44.277-05:00">INTERIM</status_change>
            <status_change date="2014-01-06T04:00:30.769-05:00">INTERIM</status_change>
            <status_change date="2014-01-27T04:00:09.498-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:20216 - extended definitions of OS are without SP checks" date="2014-07-28T18:04:00.247-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T18:06:30.338-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:02:08.599-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 10 and vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2 / Win 8 / 2k12 and vulnerable file version">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.20861" test_ref="oval:org.mitre.oval:tst:89912"/>
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.20000" test_ref="oval:org.mitre.oval:tst:80523"/>
            </criteria>
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16750" test_ref="oval:org.mitre.oval:tst:89529"/>
          </criteria>
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
        </criteria>
        <criteria operator="AND" comment="IE 11 and vulnerable file version">
          <criteria operator="OR" comment="Win 8.1 / 2k12 R2 and vulnerable file version">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8.1 is installed" definition_ref="oval:org.mitre.oval:def:18863"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9600.16476" test_ref="oval:org.mitre.oval:tst:90069"/>
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:19265" version="5" class="vulnerability">
      <metadata>
        <title>Memory corruption vulnerability in Microsoft Internet Explorer (CVE-2013-3911) - MS13-088</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2013-3911" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3911"/>
        <description>Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2013-11-15T11:11:35">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-11-18T19:08:29.258-05:00">DRAFT</status_change>
            <status_change date="2013-12-09T04:00:16.358-05:00">INTERIM</status_change>
            <status_change date="2013-12-30T04:00:21.851-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:19265 - extended definitions of OS are without SP checks" date="2014-07-28T18:03:00.291-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T18:04:48.350-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:02:08.352-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="ie 9 on winvista/2008/win 7/2008 r2">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="win vista/2008/7/2008 r2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16520" test_ref="oval:org.mitre.oval:tst:86990"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20631" test_ref="oval:org.mitre.oval:tst:86626"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 and vulnerable file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7 / R2 / Win 8 / 2k12 and vulnerable file version">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16736" test_ref="oval:org.mitre.oval:tst:87036"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.20000" test_ref="oval:org.mitre.oval:tst:80523"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.20848" test_ref="oval:org.mitre.oval:tst:87041"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:19243" version="5" class="vulnerability">
      <metadata>
        <title>Memory corruption vulnerability in Microsoft Internet Explorer (CVE-2013-3915) - MS13-088</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2013-3915" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3915"/>
        <description>Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3917.</description>
        <oval_repository>
          <dates>
            <submitted date="2013-11-15T11:11:35">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-11-18T19:08:31.786-05:00">DRAFT</status_change>
            <status_change date="2013-12-09T04:00:15.715-05:00">INTERIM</status_change>
            <status_change date="2013-12-30T04:00:21.223-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:19243 - extended definitions of OS are without SP checks" date="2014-07-28T18:03:00.291-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T18:04:46.410-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:02:08.062-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="ie6">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="either os">
            <criteria operator="AND" comment="ie6 on win xp">
              <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
              <criterion comment="Check if the version of mshtml.dll is less than 6.0.2900.6462" test_ref="oval:org.mitre.oval:tst:86575"/>
            </criteria>
            <criteria operator="AND" comment="ie 6 on win xp 64 bit, server 2003 (32+64+ia64)">
              <criteria operator="OR" comment="either of the os">
                <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5238" test_ref="oval:org.mitre.oval:tst:87268"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="ie7">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="either os">
            <criteria operator="AND" comment="win xp/server 2003">
              <criteria operator="OR" comment="either os">
                <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
                <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21359" test_ref="oval:org.mitre.oval:tst:86325"/>
            </criteria>
            <criteria operator="AND" comment="vista/server 2008">
              <criteria operator="OR" comment="either os">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.18961" test_ref="oval:org.mitre.oval:tst:87153"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23244" test_ref="oval:org.mitre.oval:tst:86327"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="ie 8 on win xp/2003/vista/2008/win 7/2008 R2">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="either os">
            <criteria operator="AND" comment="win xp/server 2003">
              <criteria operator="OR" comment="either os">
                <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
                <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23536" test_ref="oval:org.mitre.oval:tst:87313"/>
            </criteria>
            <criteria operator="AND" comment="vista/server 2008">
              <criteria operator="OR" comment="either os">
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19483" test_ref="oval:org.mitre.oval:tst:87230"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23536" test_ref="oval:org.mitre.oval:tst:87313"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="win 7/server 2008 r2 and version">
              <criteria operator="OR" comment="win 7/server 2008 r2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18283" test_ref="oval:org.mitre.oval:tst:86870"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22479" test_ref="oval:org.mitre.oval:tst:87072"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="ie 9 on winvista/2008/win 7/2008 r2">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="win vista/2008/7/2008 r2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16520" test_ref="oval:org.mitre.oval:tst:86990"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20631" test_ref="oval:org.mitre.oval:tst:86626"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 and vulnerable file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7 / R2 / Win 8 / 2k12 and vulnerable file version">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16736" test_ref="oval:org.mitre.oval:tst:87036"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.20000" test_ref="oval:org.mitre.oval:tst:80523"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.20848" test_ref="oval:org.mitre.oval:tst:87041"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 and vulnerable file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 8.1 / 2k12 R2 and vulnerable file version">
            <extend_definition comment="Microsoft Windows 8.1 is installed" definition_ref="oval:org.mitre.oval:def:18863"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9431.224" test_ref="oval:org.mitre.oval:tst:87282"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:19182" version="5" class="vulnerability">
      <metadata>
        <title>Memory corruption vulnerability in Microsoft Internet Explorer (CVE-2013-3912) - MS13-088</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2013-3912" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3912"/>
        <description>Microsoft Internet Explorer 8 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3916.</description>
        <oval_repository>
          <dates>
            <submitted date="2013-11-15T11:11:35">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-11-18T19:08:33.886-05:00">DRAFT</status_change>
            <status_change date="2013-12-09T04:00:14.338-05:00">INTERIM</status_change>
            <status_change date="2013-12-30T04:00:19.824-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:19182 - extended definitions of OS are without SP checks" date="2014-07-28T18:03:00.291-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T18:04:48.731-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:02:07.610-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="ie 8 on win xp/2003/vista/2008/win 7/2008 R2">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="either os">
            <criteria operator="AND" comment="win xp/server 2003">
              <criteria operator="OR" comment="either os">
                <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
                <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23536" test_ref="oval:org.mitre.oval:tst:87313"/>
            </criteria>
            <criteria operator="AND" comment="vista/server 2008">
              <criteria operator="OR" comment="either os">
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19483" test_ref="oval:org.mitre.oval:tst:87230"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23536" test_ref="oval:org.mitre.oval:tst:87313"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="win 7/server 2008 r2 and version">
              <criteria operator="OR" comment="win 7/server 2008 r2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18283" test_ref="oval:org.mitre.oval:tst:86870"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22479" test_ref="oval:org.mitre.oval:tst:87072"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="ie 9 on winvista/2008/win 7/2008 r2">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="win vista/2008/7/2008 r2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16520" test_ref="oval:org.mitre.oval:tst:86990"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20631" test_ref="oval:org.mitre.oval:tst:86626"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 and vulnerable file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7 / R2 / Win 8 / 2k12 and vulnerable file version">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16736" test_ref="oval:org.mitre.oval:tst:87036"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.20000" test_ref="oval:org.mitre.oval:tst:80523"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.20848" test_ref="oval:org.mitre.oval:tst:87041"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 and vulnerable file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 8.1 / 2k12 R2 and vulnerable file version">
            <extend_definition comment="Microsoft Windows 8.1 is installed" definition_ref="oval:org.mitre.oval:def:18863"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9431.224" test_ref="oval:org.mitre.oval:tst:87282"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:19138" version="5" class="vulnerability">
      <metadata>
        <title>Memory corruption vulnerability in Microsoft Internet Explorer (CVE-2013-3917) - MS13-088</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2013-3917" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3917"/>
        <description>Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3915.</description>
        <oval_repository>
          <dates>
            <submitted date="2013-11-15T11:11:35">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-11-18T19:08:37.961-05:00">DRAFT</status_change>
            <status_change date="2013-12-09T04:00:13.459-05:00">INTERIM</status_change>
            <status_change date="2013-12-30T04:00:18.894-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:19138 - extended definitions of OS are without SP checks" date="2014-07-28T18:03:00.291-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T18:04:49.012-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:02:07.138-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="ie6">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="either os">
            <criteria operator="AND" comment="ie6 on win xp">
              <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
              <criterion comment="Check if the version of mshtml.dll is less than 6.0.2900.6462" test_ref="oval:org.mitre.oval:tst:86575"/>
            </criteria>
            <criteria operator="AND" comment="ie 6 on win xp 64 bit, server 2003 (32+64+ia64)">
              <criteria operator="OR" comment="either of the os">
                <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5238" test_ref="oval:org.mitre.oval:tst:87268"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="ie7">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="either os">
            <criteria operator="AND" comment="win xp/server 2003">
              <criteria operator="OR" comment="either os">
                <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
                <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21359" test_ref="oval:org.mitre.oval:tst:86325"/>
            </criteria>
            <criteria operator="AND" comment="vista/server 2008">
              <criteria operator="OR" comment="either os">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.18961" test_ref="oval:org.mitre.oval:tst:87153"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23244" test_ref="oval:org.mitre.oval:tst:86327"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="ie 8 on win xp/2003/vista/2008/win 7/2008 R2">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="either os">
            <criteria operator="AND" comment="win xp/server 2003">
              <criteria operator="OR" comment="either os">
                <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
                <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23536" test_ref="oval:org.mitre.oval:tst:87313"/>
            </criteria>
            <criteria operator="AND" comment="vista/server 2008">
              <criteria operator="OR" comment="either os">
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19483" test_ref="oval:org.mitre.oval:tst:87230"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23536" test_ref="oval:org.mitre.oval:tst:87313"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="win 7/server 2008 r2 and version">
              <criteria operator="OR" comment="win 7/server 2008 r2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18283" test_ref="oval:org.mitre.oval:tst:86870"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22479" test_ref="oval:org.mitre.oval:tst:87072"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="ie 9 on winvista/2008/win 7/2008 r2">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="win vista/2008/7/2008 r2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16520" test_ref="oval:org.mitre.oval:tst:86990"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20631" test_ref="oval:org.mitre.oval:tst:86626"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 and vulnerable file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7 / R2 / Win 8 / 2k12 and vulnerable file version">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16736" test_ref="oval:org.mitre.oval:tst:87036"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.20000" test_ref="oval:org.mitre.oval:tst:80523"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.20848" test_ref="oval:org.mitre.oval:tst:87041"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 and vulnerable file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 8.1 / 2k12 R2 and vulnerable file version">
            <extend_definition comment="Microsoft Windows 8.1 is installed" definition_ref="oval:org.mitre.oval:def:18863"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9431.224" test_ref="oval:org.mitre.oval:tst:87282"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:19136" version="9" class="vulnerability">
      <metadata>
        <title>Cross-site scripting vulnerability in Microsoft SharePoint (CVE-2013-3180) - MS13-067</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft SharePoint Foundation 2010</product>
          <product>Microsoft SharePoint Foundation 2013</product>
          <product>Microsoft SharePoint Server 2010</product>
          <product>Microsoft SharePoint Server 2013</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2013-3180" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3180"/>
        <description>Cross-site scripting (XSS) vulnerability in Microsoft SharePoint Server 2010 SP1 and SP2 and 2013 allows remote attackers to inject arbitrary web script or HTML via a crafted POST request, aka "POST XSS Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2013-10-16T14:45:34">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-10-23T11:48:44.387-04:00">DRAFT</status_change>
            <status_change date="2013-11-11T04:01:51.214-05:00">INTERIM</status_change>
            <status_change date="2013-11-26T13:49:27.136-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:19136 - updated to check proper version as per bulletin." date="2014-01-16T10:58:00.923-05:00">
              <contributor organization="SecPod Technologies">Pooja Shetty</contributor>
            </modified>
            <status_change date="2014-01-16T10:59:41.814-05:00">INTERIM</status_change>
            <status_change date="2014-02-03T04:01:12.485-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:1390 - November 2014 bulletins." date="2014-11-17T17:25:00.386-05:00">
              <contributor organization="SecPod Technologies">Kumarswamy S</contributor>
            </modified>
            <status_change date="2014-11-17T17:29:49.370-05:00">INTERIM</status_change>
            <status_change date="2014-12-08T04:00:16.378-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:1569 - MS Bulletins - May 2015" date="2015-05-28T14:06:00.511-04:00">
              <contributor organization="SecPod Technologies">Kumarswamy S</contributor>
            </modified>
            <status_change date="2015-05-28T14:09:56.946-04:00">INTERIM</status_change>
            <status_change date="2015-06-15T04:00:11.388-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="foundation 2010/version">
          <criterion comment="Check if the version of onetutil.dll is less than 14.0.7105.5000" test_ref="oval:org.mitre.oval:tst:87199"/>
          <criteria operator="OR" comment="foundation 2010 sp1/sp2">
            <extend_definition comment="Microsoft SharePoint Foundation 2010 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:15661"/>
            <extend_definition comment="Microsoft SharePoint Foundation 2010 Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:19047"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="sharepoint server 2010/version">
          <criteria operator="OR" comment="sharepoint server 2010 sp1/sp2">
            <extend_definition comment="Microsoft SharePoint Server 2010 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:15614"/>
            <extend_definition comment="Microsoft SharePoint Server 2010 Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:18921"/>
          </criteria>
          <criteria operator="OR" comment="either files versions">
            <criterion comment="Check if the version of microsoft.office.server.native.dll is less than 14.0.7005.1000" test_ref="oval:org.mitre.oval:tst:87074"/>
            <criterion comment="Check if the version of WdsrvWorker.dll is less than 14.0.6112.5000" test_ref="oval:org.mitre.oval:tst:87135"/>
            <criterion comment="Check if the version of xlsrv.dll is less than 14.0.7104.5000 (sharepoint server)" test_ref="oval:org.mitre.oval:tst:86965"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="foundation 2013/version">
          <criterion comment="Check if the version of Microsoft.office.server.native.dll is less than 15.0.4535.1000" test_ref="oval:org.mitre.oval:tst:87023"/>
          <extend_definition comment="Microsoft SharePoint Server 2013 is installed" definition_ref="oval:org.mitre.oval:def:16325"/>
        </criteria>
        <criteria operator="AND" comment="sharepoint foundation 2013/version">
          <extend_definition comment="Microsoft SharePoint Foundation 2013 is installed" definition_ref="oval:org.mitre.oval:def:19090"/>
          <criterion comment="Check if the version of Onfda.dll is less than 15.0.4535.1000" test_ref="oval:org.mitre.oval:tst:86497"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:19090" version="3" class="inventory">
      <metadata>
        <title>Microsoft SharePoint Foundation 2013 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Vista</platform>
          <product>Microsoft SharePoint Foundation 2013</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:sharepoint_foundation:2013"/>
        <description>Microsoft SharePoint Foundation 2013 is installed</description>
        <oval_repository>
          <dates>
            <submitted date="2013-10-16T13:16:37">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-10-23T11:48:15.530-04:00">DRAFT</status_change>
            <status_change date="2013-11-11T04:01:44.863-05:00">INTERIM</status_change>
            <status_change date="2013-11-26T13:49:25.849-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="Check if Microsoft SharePoint Foundation 2013 is installed" test_ref="oval:org.mitre.oval:tst:87180"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:19047" version="3" class="inventory">
      <metadata>
        <title>Microsoft SharePoint Foundation 2010 Service Pack 2 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Vista</platform>
          <product>Microsoft SharePoint Foundation 2010</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:sharepoint_foundation:2010:sp2"/>
        <description>Microsoft SharePoint Foundation 2010 Service Pack 2 is installed</description>
        <oval_repository>
          <dates>
            <submitted date="2013-10-16T14:45:34">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-10-23T11:48:10.996-04:00">DRAFT</status_change>
            <status_change date="2013-11-11T04:01:34.923-05:00">INTERIM</status_change>
            <status_change date="2013-11-26T13:49:24.234-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Microsoft SharePoint Foundation 2010 is installed" definition_ref="oval:org.mitre.oval:def:12224"/>
        <criterion comment="Check if Microsoft SharePoint Foundation 2010 SP2 is installed" test_ref="oval:org.mitre.oval:tst:87020"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:16325" version="3" class="inventory">
      <metadata>
        <title>Microsoft SharePoint Server 2013 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Vista</platform>
          <product>Microsoft SharePoint Server 2013</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:sharepoint_server:2013"/>
        <description>Microsoft SharePoint Server 2013 is installed</description>
        <oval_repository>
          <dates>
            <submitted date="2013-04-12T10:24:08">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-04-15T21:05:34.844-04:00">DRAFT</status_change>
            <status_change date="2013-05-06T04:02:05.965-04:00">INTERIM</status_change>
            <status_change date="2013-05-27T04:00:08.177-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="Check if SharePoint Server 2013 is installed" test_ref="oval:org.mitre.oval:tst:80504"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:19112" version="3" class="vulnerability">
      <metadata>
        <title>Digital Signatures Vulnerability (CVE-2013-3869) - MS13-095</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2013-3869" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3869"/>
        <description>Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allow remote attackers to cause a denial of service (daemon hang) via a web-service request containing a crafted X.509 certificate that is not properly handled during validation, aka "Digital Signatures Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2013-11-15T09:07:14">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-11-18T19:11:50.589-05:00">DRAFT</status_change>
            <status_change date="2013-12-09T04:00:12.919-05:00">INTERIM</status_change>
            <status_change date="2013-12-30T04:00:20.225-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="win xp 32 bit/version">
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <criterion comment="Check if the version of Crypt32.dll is less than 5.131.2600.6459" test_ref="oval:org.mitre.oval:tst:87286"/>
        </criteria>
        <criteria operator="AND" comment="xp/2003/version">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
          </criteria>
          <criterion comment="Check if the version of Crypt32.dll is less than 5.131.3790.5235" test_ref="oval:org.mitre.oval:tst:87293"/>
        </criteria>
        <criteria operator="AND" comment="vista/server 2008/version">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
            <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of Crypt32.dll is less than 6.0.6002.18953" test_ref="oval:org.mitre.oval:tst:87026"/>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of Crypt32.dll is less than 6.0.6002.23235" test_ref="oval:org.mitre.oval:tst:87149"/>
              <criterion comment="Check if the version of crypt32.dll is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:87051"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="win 7/server 2008 R2/version">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12567"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12583"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12292"/>
            <extend_definition comment="Microsoft Windows 7 x64 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12627"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of Crypt32.dll is less than 6.1.7601.18277" test_ref="oval:org.mitre.oval:tst:87304"/>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of Crypt32.dll is less than 6.1.7601.22473" test_ref="oval:org.mitre.oval:tst:87289"/>
              <criterion comment="Check if version of crypt32.dll is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:87223"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="win 8/2012/version">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of Crypt32.dll is less than 6.2.9200.16727" test_ref="oval:org.mitre.oval:tst:87314"/>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of Crypt32.dll is less than 6.2.9200.20838" test_ref="oval:org.mitre.oval:tst:86549"/>
              <criterion comment="Check if the version of Crypt32.dll is greater than or equal to 6.2.9200.20000" test_ref="oval:org.mitre.oval:tst:87027"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="win 8.1/2012 R2/version">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows 8.1 is installed" definition_ref="oval:org.mitre.oval:def:18863"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of Crypt32.dll is less than 6.3.9600.16431" test_ref="oval:org.mitre.oval:tst:86986"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:19100" version="3" class="vulnerability">
      <metadata>
        <title>Denial of service vulnerability in Microsoft SharePoint (CVE-2013-3849) - MS13-067</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft SharePoint Server 2010</product>
          <product>Microsoft Office Web Apps</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2013-3849" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3849"/>
        <description>Microsoft Word Automation Services in SharePoint Server 2010 SP1, Word Web App 2010 SP1 in Office Web Apps 2010, Word 2003 SP3, Word 2007 SP3, Word 2010 SP1, Office Compatibility Pack SP3, and Word Viewer allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Office document, aka "Word Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3847, CVE-2013-3848, and CVE-2013-3858.</description>
        <oval_repository>
          <dates>
            <submitted date="2013-10-16T14:45:34">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-10-23T11:48:29.586-04:00">DRAFT</status_change>
            <status_change date="2013-11-11T04:01:48.195-05:00">INTERIM</status_change>
            <status_change date="2013-11-26T13:49:26.489-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="sharepoint server 2010/version">
          <extend_definition comment="Microsoft SharePoint Server 2010 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:15614"/>
          <criterion comment="Check if the version of WdsrvWorker.dll is less than 14.0.6112.5000" test_ref="oval:org.mitre.oval:tst:87135"/>
        </criteria>
        <criteria operator="AND" comment="web apps/version">
          <extend_definition comment="Microsoft Office Web Apps 2010 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:15860"/>
          <criterion comment="Check if the version of msoserver.dll is less than 14.0.7106.5000" test_ref="oval:org.mitre.oval:tst:87179"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:19089" version="5" class="vulnerability">
      <metadata>
        <title>InformationCardSigninHelper Vulnerability (CVE-2013-3918) - MS13-090</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2013-3918" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3918"/>
        <description>The InformationCardSigninHelper Class ActiveX control in icardie.dll in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds write) via a crafted web page that is accessed by Internet Explorer, as exploited in the wild in November 2013, aka "InformationCardSigninHelper Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2013-11-15T12:46:43">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-11-18T19:14:21.268-05:00">DRAFT</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:26275 - The test oval:org.mitre.oval:obj:26275 contains 3 slash symbols in a &lt;key> tag. It was fixed." date="2013-11-21T13:21:00.200-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-12-09T04:00:12.432-05:00">INTERIM</status_change>
            <status_change date="2013-12-30T04:00:19.611-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="either os">
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
          <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
          <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
          <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
          <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
          <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
          <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
          <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
          <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
          <extend_definition comment="Microsoft Windows 7 (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12292"/>
          <extend_definition comment="Microsoft Windows 7 x64 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12627"/>
          <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12567"/>
          <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12583"/>
          <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
          <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
          <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          <extend_definition comment="Microsoft Windows 8.1 is installed" definition_ref="oval:org.mitre.oval:def:18863"/>
        </criteria>
        <criteria operator="OR" comment="patch check">
          <criterion comment="Check if {19916e01-b44e-4e31-94a4-4696df46157b} ActiveX kill bit does not exist" test_ref="oval:org.mitre.oval:tst:86955"/>
          <criterion comment="Check if {19916e01-b44e-4e31-94a4-4696df46157b} kill bit is not set" test_ref="oval:org.mitre.oval:tst:87271"/>
          <criterion comment="Check if {c2c4f00a-720e-4389-aeb9-e9c4b0d93c6f} ActiveX kill bit does not exist" test_ref="oval:org.mitre.oval:tst:86800"/>
          <criterion comment="Check if {c2c4f00a-720e-4389-aeb9-e9c4b0d93c6f} kill bit is not set" test_ref="oval:org.mitre.oval:tst:87261"/>
          <criterion comment="Check if {53001f3a-f5e1-4b90-9c9f-00e09b53c5f1} ActiveX kill bit does not exist" test_ref="oval:org.mitre.oval:tst:87167"/>
          <criterion comment="Check if {53001f3a-f5e1-4b90-9c9f-00e09b53c5f1} kill bit is not set" test_ref="oval:org.mitre.oval:tst:86908"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:19060" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability (CVE-2013-3873) - MS13-080</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <product>Microsoft Internet Explorer 10</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2013-3873" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3873"/>
        <description>Microsoft Internet Explorer 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3872, CVE-2013-3882, and CVE-2013-3885.</description>
        <oval_repository>
          <dates>
            <submitted date="2013-10-15T09:59:37">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-10-17T11:52:27.441-04:00">DRAFT</status_change>
            <status_change date="2013-11-11T04:01:39.791-05:00">INTERIM</status_change>
            <status_change date="2013-11-26T13:49:24.919-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:19060 - extended definitions of OS are without SP checks" date="2014-07-28T18:03:00.291-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T18:04:47.276-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:02:06.311-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
        <criteria operator="OR" comment="Win 7 / R2 / Win 8 / 2k12 and vulnerable file version">
          <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
          <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
          <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
          <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
          <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
        </criteria>
        <criteria operator="OR" comment="Check for vulnerable version">
          <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16721" test_ref="oval:org.mitre.oval:tst:86866"/>
          <criteria operator="AND" comment="Check for LDR">
            <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.20000" test_ref="oval:org.mitre.oval:tst:80523"/>
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.20831" test_ref="oval:org.mitre.oval:tst:87045"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:18989" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability (CVE-2013-3897) - MS13-080</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2013-3897" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3897"/>
        <description>Use-after-free vulnerability in the CDisplayPointer class in mshtml.dll in Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted JavaScript code that uses the onpropertychange event handler, as exploited in the wild in September and October 2013, aka "Internet Explorer Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2013-10-15T09:59:37">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-10-17T11:52:22.841-04:00">DRAFT</status_change>
            <status_change date="2013-11-11T04:01:17.676-05:00">INTERIM</status_change>
            <status_change date="2013-11-26T13:49:20.734-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:18989 - extended definitions of OS are without SP checks" date="2014-07-28T18:03:00.291-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T18:04:45.724-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:02:06.022-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="ie6">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="either os">
            <criteria operator="AND" comment="ie6 on win xp">
              <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
              <criterion comment="Check if the version of mshtml.dll is less than 6.0.2900.6452" test_ref="oval:org.mitre.oval:tst:86820"/>
            </criteria>
            <criteria operator="AND" comment="ie 6 on win xp 64 bit, server 2003 (32+64+ia64)">
              <criteria operator="OR" comment="either of the os">
                <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5226" test_ref="oval:org.mitre.oval:tst:86832"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="ie7">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="either os">
            <criteria operator="AND" comment="win xp/server 2003">
              <criteria operator="OR" comment="either os">
                <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
                <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21357" test_ref="oval:org.mitre.oval:tst:86909"/>
            </criteria>
            <criteria operator="AND" comment="vista/server 2008">
              <criteria operator="OR" comment="either os">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.18945" test_ref="oval:org.mitre.oval:tst:86593"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23226" test_ref="oval:org.mitre.oval:tst:87007"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="ie 8 on win xp/2003/vista/2008/win 7/2008 R2">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="either os">
            <criteria operator="AND" comment="win xp/server 2003">
              <criteria operator="OR" comment="either os">
                <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
                <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23532" test_ref="oval:org.mitre.oval:tst:87046"/>
            </criteria>
            <criteria operator="AND" comment="vista/server 2008">
              <criteria operator="OR" comment="either os">
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19475" test_ref="oval:org.mitre.oval:tst:86894"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23532" test_ref="oval:org.mitre.oval:tst:87046"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="win 7/server 2008 r2 and version">
              <criteria operator="OR" comment="win 7/server 2008 r2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18269" test_ref="oval:org.mitre.oval:tst:86964"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22464" test_ref="oval:org.mitre.oval:tst:86867"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="ie 9 on winvista/2008/win 7/2008 r2">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="win vista/2008/7/2008 r2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16514" test_ref="oval:org.mitre.oval:tst:87018"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20625" test_ref="oval:org.mitre.oval:tst:86985"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 and vulnerable file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7 / R2 / Win 8 / 2k12 and vulnerable file version">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16721" test_ref="oval:org.mitre.oval:tst:86866"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.20000" test_ref="oval:org.mitre.oval:tst:80523"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.20831" test_ref="oval:org.mitre.oval:tst:87045"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:18988" version="3" class="vulnerability">
      <metadata>
        <title>Denial of service vulnerability in Microsoft SharePoint (CVE-2013-3847) - MS13-067</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft SharePoint Server 2010</product>
          <product>Microsoft Office Web Apps</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2013-3847" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3847"/>
        <description>Microsoft Word Automation Services in SharePoint Server 2010 SP1, Word Web App 2010 SP1 in Office Web Apps 2010, Word 2003 SP3, Word 2007 SP3, Word 2010 SP1, Office Compatibility Pack SP3, and Word Viewer allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Office document, aka "Word Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3848, CVE-2013-3849, and CVE-2013-3858.</description>
        <oval_repository>
          <dates>
            <submitted date="2013-10-16T14:45:34">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-10-23T11:48:26.744-04:00">DRAFT</status_change>
            <status_change date="2013-11-11T04:01:17.125-05:00">INTERIM</status_change>
            <status_change date="2013-11-26T13:49:20.571-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="sharepoint server 2010/version">
          <extend_definition comment="Microsoft SharePoint Server 2010 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:15614"/>
          <criterion comment="Check if the version of WdsrvWorker.dll is less than 14.0.6112.5000" test_ref="oval:org.mitre.oval:tst:87135"/>
        </criteria>
        <criteria operator="AND" comment="web apps/version">
          <extend_definition comment="Microsoft Office Web Apps 2010 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:15860"/>
          <criterion comment="Check if the version of msoserver.dll is less than 14.0.7106.5000" test_ref="oval:org.mitre.oval:tst:87179"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:18975" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability (CVE-2013-3204) - MS13-069</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2013-3204" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3204"/>
        <description>Microsoft Internet Explorer 7 through 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2013-09-13T17:32:25">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-09-17T09:45:45.668-04:00">DRAFT</status_change>
            <status_change date="2013-10-07T04:11:33.606-04:00">INTERIM</status_change>
            <status_change date="2013-10-28T04:00:49.550-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:18975 - extended definitions of OS are without SP checks" date="2014-07-28T18:01:00.642-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T18:03:08.306-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:02:05.734-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="ie7">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="either os">
            <criteria operator="AND" comment="win xp/server 2003">
              <criteria operator="OR" comment="either os">
                <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
                <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21352" test_ref="oval:org.mitre.oval:tst:86316"/>
            </criteria>
            <criteria operator="AND" comment="vista/server 2008">
              <criteria operator="OR" comment="either os">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="gdr/ldr">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.18910" test_ref="oval:org.mitre.oval:tst:86733"/>
                <criteria operator="AND" comment="ldr range">
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23183" test_ref="oval:org.mitre.oval:tst:85889"/>
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.20000" test_ref="oval:org.mitre.oval:tst:80523"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="ie 8 on win xp/2003/vista/2008/win 7/2008 R2">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="either os">
            <criteria operator="AND" comment="win xp/server 2003">
              <criteria operator="OR" comment="either os">
                <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
                <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23520" test_ref="oval:org.mitre.oval:tst:86705"/>
            </criteria>
            <criteria operator="AND" comment="vista/server 2008">
              <criteria operator="OR" comment="either os">
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
              </criteria>
              <criteria operator="OR" comment="gdr/ldr">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19458" test_ref="oval:org.mitre.oval:tst:86484"/>
                <criteria operator="AND" comment="ldr range">
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23520" test_ref="oval:org.mitre.oval:tst:86705"/>
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="win 7/server 2008 r2 and version">
              <criteria operator="OR" comment="win 7/server 2008 r2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="gdr/ldr">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18228" test_ref="oval:org.mitre.oval:tst:86192"/>
                <criteria operator="AND" comment="ldr range">
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22410" test_ref="oval:org.mitre.oval:tst:85906"/>
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="ie 9 on winvista/2008/win 7/2008 r2">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="win vista/2008/7/2008 r2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16506" test_ref="oval:org.mitre.oval:tst:86531"/>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20617" test_ref="oval:org.mitre.oval:tst:85921"/>
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="ie 10 on win 7/2008 r2/win 8/server 2012">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="ie 10 on win 7/2008 r2/win 8/server 2012">
            <criteria operator="AND" comment="win 7/2008 r2 and version">
              <criteria operator="OR" comment="win 7/2008 r2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="gdr/ldr">
                <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16686" test_ref="oval:org.mitre.oval:tst:86004"/>
                <criteria operator="AND" comment="ldr range">
                  <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.20794" test_ref="oval:org.mitre.oval:tst:86689"/>
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.20000" test_ref="oval:org.mitre.oval:tst:80523"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="win 8/2012 and version">
              <criteria operator="OR" comment="win 8/2012">
                <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
                <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
                <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
              </criteria>
              <criteria operator="OR" comment="gdr/ldr">
                <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16688" test_ref="oval:org.mitre.oval:tst:86710"/>
                <criteria operator="AND" comment="ldr range">
                  <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.20796" test_ref="oval:org.mitre.oval:tst:86427"/>
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.20000" test_ref="oval:org.mitre.oval:tst:80523"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:18964" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability (CVE-2013-3207) - MS13-069</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Vista</platform>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2013-3207" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3207"/>
        <description>Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3201, CVE-2013-3203, CVE-2013-3206, and CVE-2013-3209.</description>
        <oval_repository>
          <dates>
            <submitted date="2013-09-13T17:32:25">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-09-17T09:45:33.778-04:00">DRAFT</status_change>
            <status_change date="2013-10-07T04:11:32.380-04:00">INTERIM</status_change>
            <status_change date="2013-10-28T04:00:48.382-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:18964 - extended definitions of OS are without SP checks" date="2014-07-28T18:01:00.642-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T18:03:03.923-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:02:05.480-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="ie 9 on winvista/2008/win 7/2008 r2">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="win vista/2008/7/2008 r2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16506" test_ref="oval:org.mitre.oval:tst:86531"/>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20617" test_ref="oval:org.mitre.oval:tst:85921"/>
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="ie 10 on win 7/2008 r2/win 8/server 2012">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="ie 10 on win 7/2008 r2/win 8/server 2012">
            <criteria operator="AND" comment="win 7/2008 r2 and version">
              <criteria operator="OR" comment="win 7/2008 r2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="gdr/ldr">
                <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16686" test_ref="oval:org.mitre.oval:tst:86004"/>
                <criteria operator="AND" comment="ldr range">
                  <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.20794" test_ref="oval:org.mitre.oval:tst:86689"/>
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.20000" test_ref="oval:org.mitre.oval:tst:80523"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="win 8/2012 and version">
              <criteria operator="OR" comment="win 8/2012">
                <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
                <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
                <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
              </criteria>
              <criteria operator="OR" comment="gdr/ldr">
                <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16688" test_ref="oval:org.mitre.oval:tst:86710"/>
                <criteria operator="AND" comment="ldr range">
                  <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.20796" test_ref="oval:org.mitre.oval:tst:86427"/>
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.20000" test_ref="oval:org.mitre.oval:tst:80523"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:18951" version="3" class="vulnerability">
      <metadata>
        <title>Win32k Elevation of Privilege Vulnerability (CVE-2013-3866) - MS13-076</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2013-3866" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3866"/>
        <description>win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT allows local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2013-09-13T17:32:25">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-09-17T09:59:24.954-04:00">DRAFT</status_change>
            <status_change date="2013-10-07T04:11:30.717-04:00">INTERIM</status_change>
            <status_change date="2013-10-28T04:00:46.948-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="XP x86">
          <criterion comment="Check if the version of Win32k.sys is less than 5.1.2600.6436" test_ref="oval:org.mitre.oval:tst:86748"/>
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
        </criteria>
        <criteria operator="AND" comment="XP/2K3 and vulnerable file version">
          <criteria operator="OR" comment="XP/2K3">
            <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
          </criteria>
          <criterion comment="Check if the version of Win32k.sys is less than 5.2.3790.5210" test_ref="oval:org.mitre.oval:tst:86056"/>
        </criteria>
        <criteria operator="AND" comment="Vista/2K8 and vulnerable file version">
          <criteria operator="OR" comment="Vista/2K8">
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
            <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of Win32k.sys is less than 6.0.6002.18912" test_ref="oval:org.mitre.oval:tst:86366"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is less than 6.0.6002.23185" test_ref="oval:org.mitre.oval:tst:86704"/>
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:81723"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="7/2K8 R2 and vulnerable file version">
          <criteria operator="OR" comment="7/2K8 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12292"/>
            <extend_definition comment="Microsoft Windows 7 x64 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12627"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12567"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12583"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of Win32k.sys is less than 6.1.7601.18233" test_ref="oval:org.mitre.oval:tst:86683"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is less than 6.1.7601.22416" test_ref="oval:org.mitre.oval:tst:86771"/>
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:81763"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="8/2k12 and vulnerable file version">
          <criteria operator="OR" comment="8/2k12">
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of Win32k.sys is less than 6.2.9200.16681" test_ref="oval:org.mitre.oval:tst:86515"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is less than 6.2.9200.20789" test_ref="oval:org.mitre.oval:tst:86732"/>
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.2.9200.20000" test_ref="oval:org.mitre.oval:tst:80697"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:18942" version="3" class="vulnerability">
      <metadata>
        <title>Word memory corruption vulnerability in Microsoft SharePoint (CVE-2013-3857) - MS13-067</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft SharePoint Server 2010</product>
          <product>Microsoft Office Web Apps</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2013-3857" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3857"/>
        <description>Microsoft Word Automation Services in SharePoint Server 2010 SP1 and SP2, Word Web App 2010 SP1 and SP2 in Office Web Apps 2010, Word 2003 SP3, Word 2007 SP3, Word 2010 SP1 and SP2, Office Compatibility Pack SP3, and Word Viewer allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Office document, aka "Word Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2013-10-16T14:45:34">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-10-23T11:48:36.867-04:00">DRAFT</status_change>
            <status_change date="2013-11-11T04:01:04.763-05:00">INTERIM</status_change>
            <status_change date="2013-11-26T13:49:18.228-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="sharepoint server 2010/version">
          <criteria operator="OR" comment="sharepoint server 2010 sp1/sp2">
            <extend_definition comment="Microsoft SharePoint Server 2010 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:15614"/>
            <extend_definition comment="Microsoft SharePoint Server 2010 Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:18921"/>
          </criteria>
          <criterion comment="Check if the version of WdsrvWorker.dll is less than 14.0.6112.5000" test_ref="oval:org.mitre.oval:tst:87135"/>
        </criteria>
        <criteria operator="AND" comment="web apps/version">
          <criteria operator="OR" comment="office web apps sp1/sp2">
            <extend_definition comment="Microsoft Office Web Apps 2010 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:15860"/>
            <extend_definition comment="Microsoft Office Web Apps 2010 Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:19186"/>
          </criteria>
          <criterion comment="Check if the version of msoserver.dll is less than 14.0.7106.5000" test_ref="oval:org.mitre.oval:tst:87179"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:19186" version="6" class="inventory">
      <metadata>
        <title>Microsoft Office Web Apps 2010 Service Pack 2 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Office Web Apps 2010</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:office_web_apps:2010:sp2"/>
        <description>Microsoft Office Web Apps 2010 Service Pack 2 is installed</description>
        <oval_repository>
          <dates>
            <submitted date="2013-10-16T14:45:34">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-10-23T11:48:16.599-04:00">DRAFT</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:26572 - '\' precedding '_' removed in object regex;un-deprecated registry state" date="2013-11-08T09:48:00.143-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-11-26T13:49:28.297-05:00">INTERIM</status_change>
            <status_change date="2013-12-16T04:01:31.088-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:26572 - In some &quot;pattern match&quot; strings added &quot;\&quot; before &quot;.&quot; to clarify if &quot;point&quot; or &quot;any symbol&quot; needed." date="2014-07-28T18:11:00.493-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-07-28T18:14:47.701-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:02:07.926-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Microsoft Office Web Apps 2010 is installed" definition_ref="oval:org.mitre.oval:def:15787"/>
        <criterion comment="Check if Microsoft Office Web Apps 2010 SP2 is installed" test_ref="oval:org.mitre.oval:tst:86576"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:18921" version="5" class="inventory">
      <metadata>
        <title>Microsoft SharePoint Server 2010 Service Pack 2 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <product>Microsoft SharePoint Server 2010</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:sharepoint_server:2010:sp2"/>
        <description>Microsoft SharePoint Server 2010 SP2 is installed</description>
        <oval_repository>
          <dates>
            <submitted date="2013-10-16T14:45:34">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-10-23T11:48:12.179-04:00">DRAFT</status_change>
            <status_change date="2013-11-11T04:00:58.881-05:00">INTERIM</status_change>
            <status_change date="2013-11-26T13:49:16.818-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:23979 - ms14-001, new registry tst to detect SP's properly, def:18921 15614 updated to check display version" date="2014-01-21T16:50:00.071-05:00">
              <contributor organization="SecPod Technologies">Pooja Shetty</contributor>
            </modified>
            <status_change date="2014-01-21T17:03:44.673-05:00">INTERIM</status_change>
            <status_change date="2014-02-10T04:00:10.747-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Microsoft Office SharePoint Server 2010 is installed." definition_ref="oval:org.mitre.oval:def:12880"/>
        <criterion comment="Check if Microsoft SharePoint 2010 SP2 is installed" test_ref="oval:org.mitre.oval:tst:86608"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:18936" version="6" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability (CVE-2013-3871) - MS13-088</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2013-3871" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3871"/>
        <description>Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2013-10-15T09:59:37">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-10-17T11:52:09.897-04:00">DRAFT</status_change>
            <status_change date="2013-11-11T04:01:02.692-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:18936 - Microsoft bulletin for November 2013. Def:18936 is revised according to MS13-088 and MS13-080 v1.3." date="2013-11-18T18:56:00.506-05:00">
              <contributor organization="SecPod Technologies">Sharath S</contributor>
            </modified>
            <status_change date="2013-12-09T04:00:10.918-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:18936 - extended definitions of OS are without SP checks" date="2014-07-28T18:03:00.291-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T18:04:49.861-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:02:05.165-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="ie6">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="either os">
            <criteria operator="AND" comment="ie6 on win xp">
              <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
              <criterion comment="Check if the version of mshtml.dll is less than 6.0.2900.6462" test_ref="oval:org.mitre.oval:tst:86575"/>
            </criteria>
            <criteria operator="AND" comment="ie 6 on win xp 64 bit, server 2003 (32+64+ia64)">
              <criteria operator="OR" comment="either of the os">
                <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5238" test_ref="oval:org.mitre.oval:tst:87268"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="ie7">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="either os">
            <criteria operator="AND" comment="win xp/server 2003">
              <criteria operator="OR" comment="either os">
                <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
                <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21359" test_ref="oval:org.mitre.oval:tst:86325"/>
            </criteria>
            <criteria operator="AND" comment="vista/server 2008">
              <criteria operator="OR" comment="either os">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.18961" test_ref="oval:org.mitre.oval:tst:87153"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23244" test_ref="oval:org.mitre.oval:tst:86327"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="ie 8 on win xp/2003/vista/2008/win 7/2008 R2">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="either os">
            <criteria operator="AND" comment="win xp/server 2003">
              <criteria operator="OR" comment="either os">
                <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
                <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23536" test_ref="oval:org.mitre.oval:tst:87313"/>
            </criteria>
            <criteria operator="AND" comment="vista/server 2008">
              <criteria operator="OR" comment="either os">
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19483" test_ref="oval:org.mitre.oval:tst:87230"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23536" test_ref="oval:org.mitre.oval:tst:87313"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="win 7/server 2008 r2 and version">
              <criteria operator="OR" comment="win 7/server 2008 r2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18283" test_ref="oval:org.mitre.oval:tst:86870"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22479" test_ref="oval:org.mitre.oval:tst:87072"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="ie 9 on winvista/2008/win 7/2008 r2">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="win vista/2008/7/2008 r2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16520" test_ref="oval:org.mitre.oval:tst:86990"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20631" test_ref="oval:org.mitre.oval:tst:86626"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 and vulnerable file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7 / R2 / Win 8 / 2k12 and vulnerable file version">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16736" test_ref="oval:org.mitre.oval:tst:87036"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.20000" test_ref="oval:org.mitre.oval:tst:80523"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.20848" test_ref="oval:org.mitre.oval:tst:87041"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:18916" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability (CVE-2013-3203) - MS13-069</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Vista</platform>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2013-3203" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3203"/>
        <description>Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3201, CVE-2013-3206, CVE-2013-3207, and CVE-2013-3209.</description>
        <oval_repository>
          <dates>
            <submitted date="2013-09-13T17:32:25">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-09-17T09:45:52.540-04:00">DRAFT</status_change>
            <status_change date="2013-10-07T04:11:25.330-04:00">INTERIM</status_change>
            <status_change date="2013-10-28T04:00:42.807-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:18916 - extended definitions of OS are without SP checks" date="2014-07-28T18:01:00.642-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T18:03:07.856-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:02:04.805-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="ie 9 on winvista/2008/win 7/2008 r2">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="win vista/2008/7/2008 r2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16506" test_ref="oval:org.mitre.oval:tst:86531"/>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20617" test_ref="oval:org.mitre.oval:tst:85921"/>
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="ie 10 on win 7/2008 r2/win 8/server 2012">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="ie 10 on win 7/2008 r2/win 8/server 2012">
            <criteria operator="AND" comment="win 7/2008 r2 and version">
              <criteria operator="OR" comment="win 7/2008 r2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="gdr/ldr">
                <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16686" test_ref="oval:org.mitre.oval:tst:86004"/>
                <criteria operator="AND" comment="ldr range">
                  <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.20794" test_ref="oval:org.mitre.oval:tst:86689"/>
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.20000" test_ref="oval:org.mitre.oval:tst:80523"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="win 8/2012 and version">
              <criteria operator="OR" comment="win 8/2012">
                <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
                <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
                <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
              </criteria>
              <criteria operator="OR" comment="gdr/ldr">
                <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16688" test_ref="oval:org.mitre.oval:tst:86710"/>
                <criteria operator="AND" comment="ldr range">
                  <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.20796" test_ref="oval:org.mitre.oval:tst:86427"/>
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.20000" test_ref="oval:org.mitre.oval:tst:80523"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:18912" version="3" class="vulnerability">
      <metadata>
        <title>App Container Elevation of Privilege Vulnerability (CVE-2013-3880) - MS13-081</title>
        <affected family="windows">
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2013-3880" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3880"/>
        <description>The App Container feature in the kernel-mode drivers in Microsoft Windows 8, Windows Server 2012, and Windows RT allows remote attackers to bypass intended access restrictions and obtain sensitive information from a different container via a Trojan horse application, aka "App Container Elevation of Privilege Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2013-10-15T15:40:52">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-10-17T11:49:23.500-04:00">DRAFT</status_change>
            <status_change date="2013-11-11T04:00:58.437-05:00">INTERIM</status_change>
            <status_change date="2013-11-26T13:49:16.688-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="win 8/server 2012">
          <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
          <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
          <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
        </criteria>
        <criteria operator="OR" comment="gdr/ldr">
          <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.16699" test_ref="oval:org.mitre.oval:tst:86941"/>
          <criteria operator="AND" comment="ldr range">
            <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.20807" test_ref="oval:org.mitre.oval:tst:86991"/>
            <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.2.9200.20000" test_ref="oval:org.mitre.oval:tst:80697"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:18899" version="3" class="vulnerability">
      <metadata>
        <title>TrueType Font CMAP Table Vulnerability (CVE-2013-3894) - MS13-081</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2013-3894" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3894"/>
        <description>The kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT allow remote attackers to execute arbitrary code via a crafted CMAP table in a TrueType font (TTF) file, aka "TrueType Font CMAP Table Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2013-10-15T15:40:52">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-10-17T11:48:58.896-04:00">DRAFT</status_change>
            <status_change date="2013-11-11T04:00:53.399-05:00">INTERIM</status_change>
            <status_change date="2013-11-26T13:49:15.325-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="xp sp3/version">
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <criterion comment="Check if the version of win32k.sys is less than 5.1.2600.6442" test_ref="oval:org.mitre.oval:tst:86763"/>
        </criteria>
        <criteria operator="AND" comment="win xp/server 2003/versions">
          <criteria operator="OR" comment="xp/server 2003">
            <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
          </criteria>
          <criterion comment="Check if the version of win32k.sys is less than 5.2.3790.5216" test_ref="oval:org.mitre.oval:tst:86519"/>
        </criteria>
        <criteria operator="AND" comment="vista/2008/version">
          <criteria operator="OR" comment="vista/2008">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
            <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.0.6002.18927" test_ref="oval:org.mitre.oval:tst:86538"/>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of win32k.sys is less than 6.0.6002.23204" test_ref="oval:org.mitre.oval:tst:86561"/>
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:81723"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="win 7/2008 r2/versions">
          <criteria operator="OR" comment="win/2008 r2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12292"/>
            <extend_definition comment="Microsoft Windows 7 x64 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12627"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12567"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12583"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.18246" test_ref="oval:org.mitre.oval:tst:87029"/>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.22435" test_ref="oval:org.mitre.oval:tst:87016"/>
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:81763"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="win 8/server 2012">
          <criteria operator="OR" comment="win 8/server 2012">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.16699" test_ref="oval:org.mitre.oval:tst:86941"/>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.20807" test_ref="oval:org.mitre.oval:tst:86991"/>
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.2.9200.20000" test_ref="oval:org.mitre.oval:tst:80697"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:18893" version="5" class="vulnerability">
      <metadata>
        <title>Memory corruption vulnerability in Microsoft Internet Explorer (CVE-2013-3914) - MS13-088</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows Vista</platform>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2013-3914" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3914"/>
        <description>Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2013-11-15T11:11:35">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-11-18T19:08:35.438-05:00">DRAFT</status_change>
            <status_change date="2013-12-09T04:00:10.513-05:00">INTERIM</status_change>
            <status_change date="2013-12-30T04:00:16.385-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:18893 - extended definitions of OS are without SP checks" date="2014-07-28T18:03:00.291-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T18:04:47.449-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:02:04.294-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="ie 9 on winvista/2008/win 7/2008 r2">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="win vista/2008/7/2008 r2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16520" test_ref="oval:org.mitre.oval:tst:86990"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20631" test_ref="oval:org.mitre.oval:tst:86626"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 and vulnerable file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7 / R2 / Win 8 / 2k12 and vulnerable file version">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16736" test_ref="oval:org.mitre.oval:tst:87036"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.20000" test_ref="oval:org.mitre.oval:tst:80523"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.20848" test_ref="oval:org.mitre.oval:tst:87041"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 and vulnerable file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 8.1 / 2k12 R2 and vulnerable file version">
            <extend_definition comment="Microsoft Windows 8.1 is installed" definition_ref="oval:org.mitre.oval:def:18863"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9431.224" test_ref="oval:org.mitre.oval:tst:87282"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:18855" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability (CVE-2013-3206) - MS13-069</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Vista</platform>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2013-3206" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3206"/>
        <description>Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3201, CVE-2013-3203, CVE-2013-3207, and CVE-2013-3209.</description>
        <oval_repository>
          <dates>
            <submitted date="2013-09-13T17:32:25">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-09-17T09:46:26.775-04:00">DRAFT</status_change>
            <status_change date="2013-10-07T04:11:17.883-04:00">INTERIM</status_change>
            <status_change date="2013-10-28T04:00:35.386-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:18855 - extended definitions of OS are without SP checks" date="2014-07-28T18:01:00.642-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T18:03:10.144-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:02:04.107-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="ie 9 on winvista/2008/win 7/2008 r2">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="win vista/2008/7/2008 r2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16506" test_ref="oval:org.mitre.oval:tst:86531"/>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20617" test_ref="oval:org.mitre.oval:tst:85921"/>
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="ie 10 on win 7/2008 r2/win 8/server 2012">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="ie 10 on win 7/2008 r2/win 8/server 2012">
            <criteria operator="AND" comment="win 7/2008 r2 and version">
              <criteria operator="OR" comment="win 7/2008 r2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="gdr/ldr">
                <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16686" test_ref="oval:org.mitre.oval:tst:86004"/>
                <criteria operator="AND" comment="ldr range">
                  <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.20794" test_ref="oval:org.mitre.oval:tst:86689"/>
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.20000" test_ref="oval:org.mitre.oval:tst:80523"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="win 8/2012 and version">
              <criteria operator="OR" comment="win 8/2012">
                <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
                <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
                <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
              </criteria>
              <criteria operator="OR" comment="gdr/ldr">
                <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16688" test_ref="oval:org.mitre.oval:tst:86710"/>
                <criteria operator="AND" comment="ldr range">
                  <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.20796" test_ref="oval:org.mitre.oval:tst:86427"/>
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.20000" test_ref="oval:org.mitre.oval:tst:80523"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:18851" version="3" class="vulnerability">
      <metadata>
        <title>Address Corruption Vulnerability in Hyper-V (CVE-2013-3898) - MS13-092</title>
        <affected family="windows">
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <product>Microsoft Hyper-V Server</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2013-3898" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3898"/>
        <description>Microsoft Windows 8 and Windows Server 2012, when Hyper-V is used, does not ensure memory-address validity, which allows guest OS users to execute arbitrary code in all guest OS instances, and allows guest OS users to cause a denial of service (host OS crash), via a guest-to-host hypercall with a crafted function parameter, aka "Address Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2013-11-15T17:39:48">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-11-18T19:18:43.012-05:00">DRAFT</status_change>
            <status_change date="2013-12-09T04:00:10.432-05:00">INTERIM</status_change>
            <status_change date="2013-12-30T04:00:17.453-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="8/2k12">
          <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
        </criteria>
        <extend_definition comment="Microsoft Windows Hyper-V is installed" definition_ref="oval:org.mitre.oval:def:19210"/>
        <criterion comment="Check if the version of Hvax64.exe is less than 6.2.9200.16729" test_ref="oval:org.mitre.oval:tst:87184"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:19210" version="3" class="inventory">
      <metadata>
        <title>Microsoft Windows Hyper-V is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <product>Microsoft Hyper-V Server</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:hyper-v_server"/>
        <description>Microsoft Windows Hyper-V is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2013-11-15T08:53:19">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-11-18T19:18:42.979-05:00">DRAFT</status_change>
            <status_change date="2013-12-09T04:00:14.833-05:00">INTERIM</status_change>
            <status_change date="2013-12-30T04:00:22.607-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="Check if the file VMMS.exe for Hyper-V exists" test_ref="oval:org.mitre.oval:tst:87182"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:18847" version="14" class="vulnerability">
      <metadata>
        <title>OpenType Font Parsing Vulnerability (CVE-2013-3128) - MS13-081, MS13-082</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <product>Microsoft .NET Framework 3.0</product>
          <product>Microsoft .NET Framework 3.5</product>
          <product>Microsoft .NET Framework 3.5.1</product>
          <product>Microsoft .NET Framework 4.0</product>
          <product>Microsoft .NET Framework 4.5</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2013-3128" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3128"/>
        <description>The kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT, and .NET Framework 3.0 SP2, 3.5, 3.5.1, 4, and 4.5, allow remote attackers to execute arbitrary code via a crafted OpenType font (OTF) file, aka "OpenType Font Parsing Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2013-10-15T15:40:52">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-10-17T11:48:08.031-04:00">DRAFT</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:81058 - MS Oct 2013 bulletin ms13-081-n-082 (.Net 2 inventory CPE added)" date="2013-10-17T11:45:00.437-04:00">
              <contributor organization="SecPod Technologies">Sharath S</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:def:18847 - The attached file contains the modified definition oval:org.mitre.oval:def:18847." date="2013-10-29T16:09:00.464-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-11-14T10:21:29.916-05:00">INTERIM</status_change>
            <status_change date="2013-12-02T04:00:08.925-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:23627 - update for ms13-081, as per the revision V2.0 for kb2862330 to systems running Windows 7 and Windows Server 2008 R2" date="2014-02-06T12:30:00.673-05:00">
              <contributor organization="SecPod Technologies">Bhavya K</contributor>
            </modified>
            <status_change date="2014-02-06T12:32:01.611-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:25.096-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:18847 - criteria update for CVE-2013-3128 as per ms13-081 and ms13-082" date="2014-03-05T13:37:00.236-05:00">
              <contributor organization="SecPod Technologies">Bhavya K</contributor>
            </modified>
            <status_change date="2014-03-05T13:38:50.763-05:00">INTERIM</status_change>
            <status_change date="2014-03-24T04:00:42.684-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:18847 - .NET Framework 3.5.1 instead .NET Framework 3.5 in Windows 8 and Windows Server 2012" date="2014-03-31T14:51:00.481-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-03-31T14:53:47.217-04:00">INTERIM</status_change>
            <status_change date="2014-04-21T04:00:20.412-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:18847 - extended definitions of OS are without SP checks" date="2014-07-28T18:03:00.291-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T18:04:51.001-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:02:03.737-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment=".net 3.0 sp2 + win xp/2k3/vista/2k8">
          <extend_definition comment="Microsoft .NET Framework 3.0 SP2 is installed" definition_ref="oval:org.mitre.oval:def:15312"/>
          <criteria operator="OR" comment="XP/2k3/2k8/Vista and vulnerable files version">
            <criteria operator="AND" comment="XP / 2K3 and vulnerable file version">
              <criteria operator="OR" comment="XP / 2K3 and vulnerable file version">
                <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
                <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of PresentationCFFRasterizerNative_v0300.dll is less than 3.0.6920.4058" test_ref="oval:org.mitre.oval:tst:86414"/>
                <criteria operator="AND" comment="LDR range">
                  <criterion comment="Check if the version of PresentationCFFRasterizerNative_v0300.dll is greater than or equal to 3.0.6920.5000" test_ref="oval:org.mitre.oval:tst:86875"/>
                  <criterion comment="Check if the version of PresentationCFFRasterizerNative_v0300.dll is less than 3.0.6920.7061" test_ref="oval:org.mitre.oval:tst:86674"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Vista / 2K8 and vulnerable file version">
              <criteria operator="OR" comment="Vista / 2K8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of presentationcffrasterizernative_v0300.dll is less than 3.0.6920.4218" test_ref="oval:org.mitre.oval:tst:86273"/>
                <criteria operator="AND" comment="LDR range">
                  <criterion comment="Check if the version of PresentationCFFRasterizerNative_v0300.dll is greater than or equal to 3.0.6920.5000" test_ref="oval:org.mitre.oval:tst:86875"/>
                  <criterion comment="Check if the version of presentationcffrasterizernative_v0300.dll is less than 3.0.6920.7062" test_ref="oval:org.mitre.oval:tst:86088"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment=".net 3.5 sp1 + win xp/2k3/vista/2k8">
          <extend_definition comment="Microsoft .NET Framework 3.5 SP1 is installed" definition_ref="oval:org.mitre.oval:def:12542"/>
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of presentationcffrasterizernative_v0300.dll is less than 3.0.6920.5459" test_ref="oval:org.mitre.oval:tst:86852"/>
            <criteria operator="AND" comment="LDR range">
              <criterion comment="Check if the version of presentationcffrasterizernative_v0300.dll is greater than or equal to 3.0.6920.6000" test_ref="oval:org.mitre.oval:tst:86772"/>
              <criterion comment="Check if the version of presentationcffrasterizernative_v0300.dll is less than 3.0.6920.7062" test_ref="oval:org.mitre.oval:tst:86088"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment=".net 4.0 + win xp/2k3/vista/2k8/win7/R2">
          <extend_definition comment="Microsoft .NET Framework 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6749"/>
          <criteria operator="OR" comment="XP/2k3/2k8/Vista/Win7/R2">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of PresentationCore.dll is less than 4.0.30319.1014" test_ref="oval:org.mitre.oval:tst:86563"/>
            <criteria operator="AND" comment="LDR range">
              <criterion comment="Check if the version of presentationcore.dll is greater than or equal to 4.0.30319.2000" test_ref="oval:org.mitre.oval:tst:81790"/>
              <criterion comment="Check if the version of PresentationCore.dll is less than 4.0.30319.2021" test_ref="oval:org.mitre.oval:tst:86973"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment=".net 4.5 + win 8/2k12/vista/2k8/win7/R2">
          <extend_definition comment="Microsoft .NET Framework 4.5 is installed" definition_ref="oval:org.mitre.oval:def:15925"/>
          <criteria operator="OR" comment="XP/2k3/2k8/Vista/Win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of wpftxt_v0400.dll is less than 4.0.30319.18059" test_ref="oval:org.mitre.oval:tst:86789"/>
            <criteria operator="AND" comment="LDR range">
              <criterion comment="Check if the version of wpftxt_v0400.dll is less than 4.0.30319.19114" test_ref="oval:org.mitre.oval:tst:86961"/>
              <criterion comment="Check if the version of wpftxt_v0400.dll is greater than or equal to 4.0.30319.19000" test_ref="oval:org.mitre.oval:tst:81537"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment=".Net 3.5 + Win 8 /2k12 and vulnerable file version">
          <extend_definition comment="Microsoft .NET Framework 3.5 SP1 is installed" definition_ref="oval:org.mitre.oval:def:12542"/>
          <criteria operator="OR" comment="Windows 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of presentationcffrasterizernative_v0300.dll is less than 3.0.6920.6409" test_ref="oval:org.mitre.oval:tst:86871"/>
            <criteria operator="AND" comment="LDR range">
              <criterion comment="Check if the version of presentationcffrasterizernative_v0300.dll is greater than or equal to 3.0.6920.7000" test_ref="oval:org.mitre.oval:tst:86566"/>
              <criterion comment="Check if the version of presentationcffrasterizernative_v0300.dll is less than 3.0.6920.7062" test_ref="oval:org.mitre.oval:tst:86088"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="xp/version">
          <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
          <criterion comment="Check if the atmfd.dll version is less than 5.1.2.236" test_ref="oval:org.mitre.oval:tst:80111"/>
        </criteria>
        <criteria operator="AND" comment="win xp/server 2003/versions">
          <criteria operator="OR" comment="xp/server 2003">
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
          </criteria>
          <criterion comment="Check if the version of atmfd.dll is less than 5.2.2.236" test_ref="oval:org.mitre.oval:tst:86993"/>
        </criteria>
        <criteria operator="AND" comment="vista/2008/version">
          <criteria operator="OR" comment="vista/2008">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <criteria operator="OR" comment="either file versions">
            <criterion comment="Check if the atmfd.dll version is less than 5.1.2.236" test_ref="oval:org.mitre.oval:tst:80111"/>
            <criterion comment="Check if the version of  Dwrite.dll is less than 7.0.6002.18923" test_ref="oval:org.mitre.oval:tst:86197"/>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of  Dwrite.dll is less than 7.0.6002.23200" test_ref="oval:org.mitre.oval:tst:86796"/>
              <criterion comment="Check if the version of Dwrite.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:81833"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="win 7/2008 r2/versions">
          <criteria operator="OR" comment="win 7/2008 r2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="either file versions">
            <criterion comment="Check if the version of atmfd.dll is less than 5.1.2.238" test_ref="oval:org.mitre.oval:tst:86983"/>
            <criterion comment="Check if the version of  Dwrite.dll is less than 6.1.7601.18245" test_ref="oval:org.mitre.oval:tst:86098"/>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of  Dwrite.dll is less than 6.1.7601.22434" test_ref="oval:org.mitre.oval:tst:86963"/>
              <criterion comment="Check if the version of Dwrite.dll is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:86567"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="win 8/server 2012">
          <criteria operator="OR" comment="win 8/server 2012">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criterion comment="Check if the atmfd.dll version is less than 5.1.2.237" test_ref="oval:org.mitre.oval:tst:80599"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:15312" version="5" class="inventory">
      <metadata>
        <title>Microsoft .NET Framework 3.0 SP2 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <product>Microsoft .NET Framework 3.0</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:.net_framework:3.0:sp2"/>
        <description>Microsoft .NET Framework 3.0 SP2 is installed</description>
        <oval_repository>
          <dates>
            <submitted date="2012-05-08T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2012-05-18T17:36:46.164-04:00">DRAFT</status_change>
            <status_change date="2012-06-04T04:01:00.137-04:00">INTERIM</status_change>
            <status_change date="2012-06-25T04:00:16.142-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:15312 - .NET Framework inventories with modified products." date="2014-03-18T14:31:00.962-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-03-18T14:33:23.907-04:00">INTERIM</status_change>
            <status_change date="2014-04-07T04:01:56.410-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="Is the Microsoft .NET Framework 3.0 installed" test_ref="oval:org.mitre.oval:tst:79733"/>
        <criterion comment="Microsoft .NET Framework 3.0 SP2 is installed" test_ref="oval:org.mitre.oval:tst:79091"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:18817" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability (CVE-2013-3885) - MS13-080</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <product>Microsoft Internet Explorer 10</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2013-3885" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3885"/>
        <description>Microsoft Internet Explorer 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3872, CVE-2013-3873, and CVE-2013-3882.</description>
        <oval_repository>
          <dates>
            <submitted date="2013-10-15T09:59:37">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-10-17T11:52:31.770-04:00">DRAFT</status_change>
            <status_change date="2013-11-11T04:00:39.447-05:00">INTERIM</status_change>
            <status_change date="2013-11-26T13:49:12.576-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:18817 - extended definitions of OS are without SP checks" date="2014-07-28T18:03:00.291-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T18:04:46.637-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:02:03.120-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
        <criteria operator="OR" comment="Win 7 / R2 / Win 8 / 2k12 and vulnerable file version">
          <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
          <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
          <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
          <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
          <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
        </criteria>
        <criteria operator="OR" comment="Check for vulnerable version">
          <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16721" test_ref="oval:org.mitre.oval:tst:86866"/>
          <criteria operator="AND" comment="Check for LDR">
            <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.20000" test_ref="oval:org.mitre.oval:tst:80523"/>
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.20831" test_ref="oval:org.mitre.oval:tst:87045"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:18813" version="3" class="vulnerability">
      <metadata>
        <title>Win32k Elevation of Privilege Vulnerability (CVE-2013-3865) - MS13-076</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2013-3865" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3865"/>
        <description>win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT allows local users to gain privileges via a crafted application, aka "Win32k Multiple Fetch Vulnerability," a different vulnerability than CVE-2013-1342, CVE-2013-1343, CVE-2013-1344, and CVE-2013-3864.</description>
        <oval_repository>
          <dates>
            <submitted date="2013-09-13T17:32:25">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-09-17T09:59:05.982-04:00">DRAFT</status_change>
            <status_change date="2013-10-07T04:11:14.532-04:00">INTERIM</status_change>
            <status_change date="2013-10-28T04:00:32.157-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="XP x86">
          <criterion comment="Check if the version of Win32k.sys is less than 5.1.2600.6436" test_ref="oval:org.mitre.oval:tst:86748"/>
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
        </criteria>
        <criteria operator="AND" comment="XP/2K3 and vulnerable file version">
          <criteria operator="OR" comment="XP/2K3">
            <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
          </criteria>
          <criterion comment="Check if the version of Win32k.sys is less than 5.2.3790.5210" test_ref="oval:org.mitre.oval:tst:86056"/>
        </criteria>
        <criteria operator="AND" comment="Vista/2K8 and vulnerable file version">
          <criteria operator="OR" comment="Vista/2K8">
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
            <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of Win32k.sys is less than 6.0.6002.18912" test_ref="oval:org.mitre.oval:tst:86366"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is less than 6.0.6002.23185" test_ref="oval:org.mitre.oval:tst:86704"/>
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:81723"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="7/2K8 R2 and vulnerable file version">
          <criteria operator="OR" comment="7/2K8 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12292"/>
            <extend_definition comment="Microsoft Windows 7 x64 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12627"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12567"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12583"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of Win32k.sys is less than 6.1.7601.18233" test_ref="oval:org.mitre.oval:tst:86683"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is less than 6.1.7601.22416" test_ref="oval:org.mitre.oval:tst:86771"/>
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:81763"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="8/2k12 and vulnerable file version">
          <criteria operator="OR" comment="8/2k12">
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of Win32k.sys is less than 6.2.9200.16681" test_ref="oval:org.mitre.oval:tst:86515"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is less than 6.2.9200.20789" test_ref="oval:org.mitre.oval:tst:86732"/>
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.2.9200.20000" test_ref="oval:org.mitre.oval:tst:80697"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:18811" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability (CVE-2013-3886) - MS13-080</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Vista</platform>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2013-3886" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3886"/>
        <description>Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2013-10-15T09:59:37">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-10-17T11:52:59.685-04:00">DRAFT</status_change>
            <status_change date="2013-11-11T04:00:37.432-05:00">INTERIM</status_change>
            <status_change date="2013-11-26T13:49:12.237-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:18811 - extended definitions of OS are without SP checks" date="2014-07-28T18:03:00.291-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T18:04:48.522-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:02:02.956-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="ie 9 on winvista/2008/win 7/2008 r2">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="win vista/2008/7/2008 r2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16514" test_ref="oval:org.mitre.oval:tst:87018"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20625" test_ref="oval:org.mitre.oval:tst:86985"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 and vulnerable file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7 / R2 / Win 8 / 2k12 and vulnerable file version">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16721" test_ref="oval:org.mitre.oval:tst:86866"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.20000" test_ref="oval:org.mitre.oval:tst:80523"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.20831" test_ref="oval:org.mitre.oval:tst:87045"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:18805" version="3" class="vulnerability">
      <metadata>
        <title>Ancillary Function Driver Information Disclosure Vulnerability (CVE-2013-3887) - MS13-093</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2013-3887" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3887"/>
        <description>The Ancillary Function Driver (AFD) in afd.sys in the kernel-mode drivers in Microsoft Windows XP SP2, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, and Windows Server 2012 allows local users to obtain sensitive information from kernel memory by leveraging improper copy operations, aka "Ancillary Function Driver Information Disclosure Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2013-11-15T14:21:24">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-11-18T19:20:24.101-05:00">DRAFT</status_change>
            <status_change date="2013-12-09T04:00:10.107-05:00">INTERIM</status_change>
            <status_change date="2013-12-30T04:00:16.891-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="XP x64 / 2k3 (x64 / ia64) and vulnerable file version">
          <criteria operator="OR" comment="XP X64 / 2k3 (x64 / ia64)">
            <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
          </criteria>
          <criterion comment="Check if the version of afd.sys is less than 5.2.3790.5217" test_ref="oval:org.mitre.oval:tst:87132"/>
        </criteria>
        <criteria operator="AND" comment="Vista x64 / 2k8 (x64 / ia64) and vulnerable file version">
          <criteria operator="OR" comment="Vista x64 / 2k8 (x64 / ia64)">
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
            <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
          </criteria>
          <criteria operator="OR" comment="LDR / GDR">
            <criterion comment="Check if the version of afd.sys is less than 6.0.6002.18928" test_ref="oval:org.mitre.oval:tst:87092"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of afd.sys is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:87004"/>
              <criterion comment="Check if the version of afd.sys is less than 6.0.6002.23207" test_ref="oval:org.mitre.oval:tst:87068"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 x64 / 2k8 R2 (x64 / ia64) and vulnerable file version">
          <criteria operator="OR" comment="Win 7 x64 / 2k8 R2 (x64 / ia64)">
            <extend_definition comment="Microsoft Windows 7 x64 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12627"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12567"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12583"/>
          </criteria>
          <criteria operator="OR" comment="LDR / GDR">
            <criterion comment="Check if the version of afd.sys is less than 6.1.7601.18272" test_ref="oval:org.mitre.oval:tst:86858"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of afd.sys is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:86897"/>
              <criterion comment="Check if the version of afd.sys is less than 6.1.7601.22467" test_ref="oval:org.mitre.oval:tst:86651"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8 / 2k12 (x64) and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="LDR / GDR">
            <criterion comment="Check if the version of afd.sys is less than 6.2.9200.16706" test_ref="oval:org.mitre.oval:tst:86861"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of afd.sys is greater than or equal to 6.2.9200.20000" test_ref="oval:org.mitre.oval:tst:87102"/>
              <criterion comment="Check if the version of afd.sys is less than 6.2.9200.20814" test_ref="oval:org.mitre.oval:tst:87014"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:18801" version="3" class="vulnerability">
      <metadata>
        <title>Memory corruption vulnerability in Microsoft SharePoint (CVE-2013-3858) - MS13-067</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Office Web Apps</product>
          <product>Microsoft SharePoint Server 2010</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2013-3858" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3858"/>
        <description>Microsoft Word Automation Services in SharePoint Server 2010 SP1, Word Web App 2010 SP1 in Office Web Apps 2010, Word 2003 SP3, Word 2007 SP3, Word 2010 SP1, Office Compatibility Pack SP3, and Word Viewer allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Office document, aka "Word Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3847, CVE-2013-3848, and CVE-2013-3849.</description>
        <oval_repository>
          <dates>
            <submitted date="2013-10-16T14:45:34">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-10-23T11:48:19.228-04:00">DRAFT</status_change>
            <status_change date="2013-11-11T04:00:36.426-05:00">INTERIM</status_change>
            <status_change date="2013-11-26T13:49:11.638-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="sharepoint server 2010/version">
          <extend_definition comment="Microsoft SharePoint Server 2010 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:15614"/>
          <criterion comment="Check if the version of WdsrvWorker.dll is less than 14.0.6112.5000" test_ref="oval:org.mitre.oval:tst:87135"/>
        </criteria>
        <criteria operator="AND" comment="web apps/version">
          <extend_definition comment="Microsoft Office Web Apps 2010 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:15860"/>
          <criterion comment="Check if the version of msoserver.dll is less than 14.0.7106.5000" test_ref="oval:org.mitre.oval:tst:87179"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:18800" version="3" class="vulnerability">
      <metadata>
        <title>Denial of service vulnerability in Microsoft SharePoint (CVE-2013-3848) - MS13-067</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft SharePoint Server 2010</product>
          <product>Microsoft Office Web Apps</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2013-3848" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3848"/>
        <description>Microsoft Word Automation Services in SharePoint Server 2010 SP1, Word Web App 2010 SP1 in Office Web Apps 2010, Word 2003 SP3, Word 2007 SP3, Word 2010 SP1, Office Compatibility Pack SP3, and Word Viewer allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Office document, aka "Word Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3847, CVE-2013-3849, and CVE-2013-3858.</description>
        <oval_repository>
          <dates>
            <submitted date="2013-10-16T14:45:34">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-10-23T11:48:39.934-04:00">DRAFT</status_change>
            <status_change date="2013-11-11T04:00:35.846-05:00">INTERIM</status_change>
            <status_change date="2013-11-26T13:49:11.524-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="sharepoint server 2010/version">
          <extend_definition comment="Microsoft SharePoint Server 2010 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:15614"/>
          <criterion comment="Check if the version of WdsrvWorker.dll is less than 14.0.6112.5000" test_ref="oval:org.mitre.oval:tst:87135"/>
        </criteria>
        <criteria operator="AND" comment="web apps/version">
          <extend_definition comment="Microsoft Office Web Apps 2010 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:15860"/>
          <criterion comment="Check if the version of msoserver.dll is less than 14.0.7106.5000" test_ref="oval:org.mitre.oval:tst:87179"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:15860" version="7" class="inventory">
      <metadata>
        <title>Microsoft Office Web Apps 2010 Service Pack 1 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Office Web Apps 2010</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:office_web_apps:2010:sp1"/>
        <description>Microsoft Office Web Apps 2010 Service Pack 1 is installed</description>
        <oval_repository>
          <dates>
            <submitted date="2012-10-17T09:07:03">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2012-10-19T16:11:26.152-04:00">DRAFT</status_change>
            <status_change date="2012-11-05T04:00:23.370-05:00">INTERIM</status_change>
            <status_change date="2012-11-26T04:00:14.164-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:24131 - Symbol \ (backslash) is not needed because symbol _ (underscore) isn't a metacharacter." date="2013-08-29T09:21:00.244-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-08-29T09:22:52.391-04:00">INTERIM</status_change>
            <status_change date="2013-09-16T04:00:21.578-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:24131 - In some &quot;pattern match&quot; strings added &quot;\&quot; before &quot;.&quot; to clarify if &quot;point&quot; or &quot;any symbol&quot; needed." date="2014-07-28T18:11:00.493-04:00">
              <contributor organization="ALTX-SOFT">Evgeniy Pavlov</contributor>
            </modified>
            <status_change date="2014-07-28T18:14:45.693-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:01:26.929-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="Check if Microsoft Office Web Apps SP1 is installed" test_ref="oval:org.mitre.oval:tst:80139"/>
        <extend_definition comment="Microsoft Office Web Apps 2010 is installed" definition_ref="oval:org.mitre.oval:def:15787"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:15787" version="3" class="inventory">
      <metadata>
        <title>Microsoft Office Web Apps 2010 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Office Web Apps 2010</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:office_web_apps:2010"/>
        <description>Microsoft Office Web Apps 2010 is installed</description>
        <oval_repository>
          <dates>
            <submitted date="2012-10-17T14:16:01">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2012-10-19T16:11:25.935-04:00">DRAFT</status_change>
            <status_change date="2012-11-05T04:00:19.815-05:00">INTERIM</status_change>
            <status_change date="2012-11-26T04:00:13.143-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="Check if Microsoft Web Apps is installed" test_ref="oval:org.mitre.oval:tst:80134"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:15614" version="7" class="inventory">
      <metadata>
        <title>Microsoft SharePoint Server 2010 Service Pack 1 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Microsoft SharePoint Server 2010</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:sharepoint_server:2010:sp1"/>
        <description>Microsoft SharePoint Server 2010 SP1 is installed</description>
        <oval_repository>
          <dates>
            <submitted date="2012-07-16T12:35:55">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2012-07-19T12:32:13.329-04:00">DRAFT</status_change>
            <status_change date="2012-08-06T04:00:12.930-04:00">INTERIM</status_change>
            <status_change date="2012-08-27T04:00:29.799-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:24062 - corrected regex (symbol '\' not needed before symbol '_')" date="2013-09-06T14:20:00.865-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-09-06T14:21:25.926-04:00">INTERIM</status_change>
            <status_change date="2013-09-23T04:00:08.343-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:19908 - ms14-001, new registry tst to detect SP's properly, def:18921 15614 updated to check display version" date="2014-01-21T16:50:00.071-05:00">
              <contributor organization="SecPod Technologies">Pooja Shetty</contributor>
            </modified>
            <status_change date="2014-01-21T17:03:44.381-05:00">INTERIM</status_change>
            <status_change date="2014-02-10T04:00:06.288-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Microsoft Office SharePoint Server 2010 is installed." definition_ref="oval:org.mitre.oval:def:12880"/>
        <criterion comment="Check if Microsoft SharePoint Server 2010 Service Pack 1 is installed" test_ref="oval:org.mitre.oval:tst:80093"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:12880" version="5" class="inventory">
      <metadata>
        <title>Microsoft Office SharePoint Server 2010 is installed.</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <product>Microsoft Office SharePoint Server 2010</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:sharepoint:2010"/>
        <description>Microsoft Office SharePoint Server 2010 is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2011-09-13T13:00:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2011-09-20T09:24:26.061-04:00">DRAFT</status_change>
            <status_change date="2011-10-10T04:00:35.882-04:00">INTERIM</status_change>
            <status_change date="2011-10-31T04:01:00.596-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:16204 - New Microsoft Patch Tuesday October 2012 definitions." date="2012-10-19T16:09:00.822-04:00">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </modified>
            <status_change date="2012-10-19T16:30:25.998-04:00">INTERIM</status_change>
            <status_change date="2012-11-05T04:00:03.694-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="SharePoint Server 2010 is installed." test_ref="oval:org.mitre.oval:tst:43555"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:18792" version="3" class="vulnerability">
      <metadata>
        <title>Win32k Elevation of Privilege Vulnerability (CVE-2013-1344) - MS13-076</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2013-1344" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1344"/>
        <description>win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT allows local users to gain privileges via a crafted application, aka "Win32k Multiple Fetch Vulnerability," a different vulnerability than CVE-2013-1342, CVE-2013-1343, CVE-2013-3864, and CVE-2013-3865.</description>
        <oval_repository>
          <dates>
            <submitted date="2013-09-13T17:32:25">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-09-17T09:59:34.597-04:00">DRAFT</status_change>
            <status_change date="2013-10-07T04:11:13.081-04:00">INTERIM</status_change>
            <status_change date="2013-10-28T04:00:30.647-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="XP x86">
          <criterion comment="Check if the version of Win32k.sys is less than 5.1.2600.6436" test_ref="oval:org.mitre.oval:tst:86748"/>
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
        </criteria>
        <criteria operator="AND" comment="XP/2K3 and vulnerable file version">
          <criteria operator="OR" comment="XP/2K3">
            <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
          </criteria>
          <criterion comment="Check if the version of Win32k.sys is less than 5.2.3790.5210" test_ref="oval:org.mitre.oval:tst:86056"/>
        </criteria>
        <criteria operator="AND" comment="Vista/2K8 and vulnerable file version">
          <criteria operator="OR" comment="Vista/2K8">
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
            <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of Win32k.sys is less than 6.0.6002.18912" test_ref="oval:org.mitre.oval:tst:86366"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is less than 6.0.6002.23185" test_ref="oval:org.mitre.oval:tst:86704"/>
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:81723"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="7/2K8 R2 and vulnerable file version">
          <criteria operator="OR" comment="7/2K8 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12292"/>
            <extend_definition comment="Microsoft Windows 7 x64 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12627"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12567"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12583"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of Win32k.sys is less than 6.1.7601.18233" test_ref="oval:org.mitre.oval:tst:86683"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is less than 6.1.7601.22416" test_ref="oval:org.mitre.oval:tst:86771"/>
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:81763"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="8/2k12 and vulnerable file version">
          <criteria operator="OR" comment="8/2k12">
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of Win32k.sys is less than 6.2.9200.16681" test_ref="oval:org.mitre.oval:tst:86515"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is less than 6.2.9200.20789" test_ref="oval:org.mitre.oval:tst:86732"/>
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.2.9200.20000" test_ref="oval:org.mitre.oval:tst:80697"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:18722" version="3" class="vulnerability">
      <metadata>
        <title>Graphics Device Interface Integer Overflow Vulnerability (CVE-2013-3940) - MS13-089</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2013-3940" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3940"/>
        <description>Integer overflow in the Graphics Device Interface (GDI) in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted image in a Windows Write (.wri) document, which is not properly handled in WordPad, aka "Graphics Device Interface Integer Overflow Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2013-11-15T13:04:03">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-11-18T19:11:52.507-05:00">DRAFT</status_change>
            <status_change date="2013-12-09T04:00:09.434-05:00">INTERIM</status_change>
            <status_change date="2013-12-30T04:00:16.046-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Check for vulnerable Windows XP SP3(x86) and gdi32.dll version">
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <criterion comment="Check if version of gdi32.dll version is less than 5.1.2600.6460" test_ref="oval:org.mitre.oval:tst:87292"/>
        </criteria>
        <criteria operator="AND" comment="Check for vulnerable Windows 2003 SP2(x86)/(x64)/(ia-64)/XP SP2(x64) and gdi32.dll version">
          <criteria operator="OR" comment="Check for vulnerable Windows 2003 SP2(x86)/(x64)/(ia-64)/XP SP2(x64)">
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
            <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
          </criteria>
          <criterion comment="Check if version of gdi32.dll version is less than 5.2.3790.5236" test_ref="oval:org.mitre.oval:tst:87237"/>
        </criteria>
        <criteria operator="AND" comment="Check for Vulnerable Windows Vista SP2(x86)/(x64)/Server 2008 SP2(x86)/(x64)/(ia-64) and gdi32.dll version">
          <criteria operator="OR" comment="Check for Vulnerable Windows Vista SP2(x86)/(x64)/Server 2008 SP2(x86)/(x64)/(ia-64)">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
            <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
          </criteria>
          <criteria operator="OR" comment="Check for LDR/GDR">
            <criterion comment="Check if version of gdi32.dll version is less than 6.0.6002.18953" test_ref="oval:org.mitre.oval:tst:87114"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if version of gdi32.dll is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:87308"/>
              <criterion comment="Check if version of gdi32.dll is less than 6.0.6002.23235" test_ref="oval:org.mitre.oval:tst:87291"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Check for Vulnerable Windows 7 SP1(x86)/(x64)/Server 2008 R2 SP1(x64)/(ia-64) and gdi32.dll version">
          <criteria operator="OR" comment="Check for Vulnerable Windows 7 SP1(x86)/(x64)/Server 2008 R2 SP1(x64)/(ia-64)">
            <extend_definition comment="Microsoft Windows 7 (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12292"/>
            <extend_definition comment="Microsoft Windows 7 x64 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12627"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12567"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12583"/>
          </criteria>
          <criteria operator="OR" comment="Check for LDR/GDR">
            <criterion comment="Check if version of gdi32.dll version is less than 6.1.7601.18275" test_ref="oval:org.mitre.oval:tst:87175"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if version of gdi32.dll is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:87215"/>
              <criterion comment="Check if version of gdi32.dll is less than 6.1.7601.22471" test_ref="oval:org.mitre.oval:tst:86601"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Check for Vulnerable Windows 8(x86)/(x64)/Server 2012 and gdi32.dll version">
          <criteria operator="OR" comment="Check for Vulnerable Windows 8(x86)/(x64)/Server 2012">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for LDR/GDR">
            <criterion comment="Check if version of gdi32.dll version is less than 6.2.9200.16728" test_ref="oval:org.mitre.oval:tst:86854"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if version of gdi32.dll is greater than or equal to 6.2.9200.20000" test_ref="oval:org.mitre.oval:tst:86843"/>
              <criterion comment="Check if version of gdi32.dll is less than 6.2.9200.20839" test_ref="oval:org.mitre.oval:tst:87222"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Check for Vulnerable Windows 8.1(x86)/(x64)/Server 2012 R2 and gdi32.dll version">
          <criteria operator="OR" comment="Check for Vulnerable Windows 8.1(x86)/(x64)/Server 2012 R2">
            <extend_definition comment="Microsoft Windows 8.1 is installed" definition_ref="oval:org.mitre.oval:def:18863"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if version of gdi32.dll version is less than 6.3.9600.16421" test_ref="oval:org.mitre.oval:tst:87101"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:18718" version="4" class="vulnerability">
      <metadata>
        <title>Win32k Use After Free Vulnerability (CVE-2013-3879) MS13-081</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2013-3879" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3879"/>
        <description>Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT allows local users to gain privileges via a crafted application, aka "Win32k Use After Free Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2013-10-15T15:40:52">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-10-17T11:47:48.508-04:00">DRAFT</status_change>
            <status_change date="2013-11-04T04:01:02.964-05:00">INTERIM</status_change>
            <status_change date="2013-11-25T04:00:40.826-05:00">ACCEPTED</status_change>
            <status_change date="2013-11-25T04:00:26.398-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="xp sp3/version">
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <criterion comment="Check if the version of win32k.sys is less than 5.1.2600.6442" test_ref="oval:org.mitre.oval:tst:86763"/>
        </criteria>
        <criteria operator="AND" comment="win xp/server 2003/versions">
          <criteria operator="OR" comment="xp/server 2003">
            <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
          </criteria>
          <criterion comment="Check if the version of win32k.sys is less than 5.2.3790.5216" test_ref="oval:org.mitre.oval:tst:86519"/>
        </criteria>
        <criteria operator="AND" comment="vista/2008/version">
          <criteria operator="OR" comment="vista/2008">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
            <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.0.6002.18927" test_ref="oval:org.mitre.oval:tst:86538"/>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of win32k.sys is less than 6.0.6002.23204" test_ref="oval:org.mitre.oval:tst:86561"/>
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:81723"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="win 7/2008 r2/versions">
          <criteria operator="OR" comment="win/2008 r2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12292"/>
            <extend_definition comment="Microsoft Windows 7 x64 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12627"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12567"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12583"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.18246" test_ref="oval:org.mitre.oval:tst:87029"/>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.22435" test_ref="oval:org.mitre.oval:tst:87016"/>
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:81763"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="win 8/server 2012">
          <criteria operator="OR" comment="win 8/server 2012">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.16699" test_ref="oval:org.mitre.oval:tst:86941"/>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.20807" test_ref="oval:org.mitre.oval:tst:86991"/>
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.2.9200.20000" test_ref="oval:org.mitre.oval:tst:80697"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:18715" version="4" class="vulnerability">
      <metadata>
        <title>Vulnerability in Windows Common Control Library Could Allow Remote Code Execution (CVE-2013-3195) - MS13-083</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2013-3195" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3195"/>
        <description>The DSA_InsertItem function in Comctl32.dll in the Windows common control library in Microsoft Windows XP SP2, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT does not properly allocate memory, which allows remote attackers to execute arbitrary code via a crafted value in an argument to an ASP.NET web application, aka "Comctl32 Integer Overflow Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2013-10-15T10:20:10">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-10-17T11:55:02.436-04:00">DRAFT</status_change>
            <status_change date="2013-11-04T04:01:01.851-05:00">INTERIM</status_change>
            <status_change date="2013-11-25T04:00:40.628-05:00">ACCEPTED</status_change>
            <status_change date="2013-11-25T04:00:26.222-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable Windows XP x64 sp2, Server 2003 x86/x64/ia64 sp2">
          <criteria operator="OR" comment="Microsoft Windows XP x64 Edition SP2, Server 2003 SP2 x86/x64/ia64">
            <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
          </criteria>
          <criterion comment="The version of Comctl32.dll is less than 5.82.3790.5190" test_ref="oval:org.mitre.oval:tst:86845"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Windows Vista x86/x64 sp2, Windows Server 2008 x86/x64/ia64 sp2">
          <criteria operator="OR" comment="Microsoft Windows Vista SP2 x64/32-bit, Server 2008 32-bit/64-bit/ia-64 sp2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
            <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
          </criteria>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="The version of Comctl32.dll is less than 5.82.6002.18879" test_ref="oval:org.mitre.oval:tst:86998"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="The version of Comctl32.dll is greater than or equal to 5.82.6002.23000" test_ref="oval:org.mitre.oval:tst:87003"/>
              <criterion comment="The version of Comctl32.dll is less than 5.82.6002.23151" test_ref="oval:org.mitre.oval:tst:86960"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Windows 7 x86/x64 SP1, Windows 2008 R2 x64/ia64 SP1">
          <criteria operator="OR" comment="Microsoft Windows 7 32-bit/x64 SP1, Windows Server 2008 R2 x64/Itanium SP1">
            <extend_definition comment="Microsoft Windows 7 (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12292"/>
            <extend_definition comment="Microsoft Windows 7 x64 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12627"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12567"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12583"/>
          </criteria>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="The version of Comctl32.dll is less than 5.82.7601.18201" test_ref="oval:org.mitre.oval:tst:87017"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="The version of Comctl32.dll is greater than or equal to 5.82.7601.22000" test_ref="oval:org.mitre.oval:tst:87052"/>
              <criterion comment="The version of Comctl32.dll is less than 5.82.7601.22376" test_ref="oval:org.mitre.oval:tst:86313"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Windows 8 x86/x64, Windows Server 2012">
          <criteria operator="OR" comment="Microsoft Windows 8 x86/x64, Windows Server 2012">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="GDR or LDR Service branch">
            <criterion comment="The version of Comctl32.dll is less than 5.82.9200.16657" test_ref="oval:org.mitre.oval:tst:86489"/>
            <criteria operator="AND" comment="LDR">
              <criterion comment="The version of Comctl32.dll is greater than or equal 5.82.9200.20000" test_ref="oval:org.mitre.oval:tst:86160"/>
              <criterion comment="The version of Comctl32.dll is less than 5.82.9200.20765" test_ref="oval:org.mitre.oval:tst:86780"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:18714" version="3" class="vulnerability">
      <metadata>
        <title>Win32k Elevation of Privilege Vulnerability (CVE-2013-1342) - MS13-076</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2013-1342" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1342"/>
        <description>win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT allows local users to gain privileges via a crafted application, aka "Win32k Multiple Fetch Vulnerability," a different vulnerability than CVE-2013-1343, CVE-2013-1344, CVE-2013-3864, and CVE-2013-3865.</description>
        <oval_repository>
          <dates>
            <submitted date="2013-09-13T17:32:25">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-09-17T09:58:36.910-04:00">DRAFT</status_change>
            <status_change date="2013-10-07T04:11:00.616-04:00">INTERIM</status_change>
            <status_change date="2013-10-28T04:00:24.713-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="XP x86">
          <criterion comment="Check if the version of Win32k.sys is less than 5.1.2600.6436" test_ref="oval:org.mitre.oval:tst:86748"/>
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
        </criteria>
        <criteria operator="AND" comment="XP/2K3 and vulnerable file version">
          <criteria operator="OR" comment="XP/2K3">
            <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
          </criteria>
          <criterion comment="Check if the version of Win32k.sys is less than 5.2.3790.5210" test_ref="oval:org.mitre.oval:tst:86056"/>
        </criteria>
        <criteria operator="AND" comment="Vista/2K8 and vulnerable file version">
          <criteria operator="OR" comment="Vista/2K8">
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
            <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of Win32k.sys is less than 6.0.6002.18912" test_ref="oval:org.mitre.oval:tst:86366"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is less than 6.0.6002.23185" test_ref="oval:org.mitre.oval:tst:86704"/>
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:81723"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="7/2K8 R2 and vulnerable file version">
          <criteria operator="OR" comment="7/2K8 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12292"/>
            <extend_definition comment="Microsoft Windows 7 x64 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12627"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12567"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12583"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of Win32k.sys is less than 6.1.7601.18233" test_ref="oval:org.mitre.oval:tst:86683"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is less than 6.1.7601.22416" test_ref="oval:org.mitre.oval:tst:86771"/>
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:81763"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="8/2k12 and vulnerable file version">
          <criteria operator="OR" comment="8/2k12">
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of Win32k.sys is less than 6.2.9200.16681" test_ref="oval:org.mitre.oval:tst:86515"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is less than 6.2.9200.20789" test_ref="oval:org.mitre.oval:tst:86732"/>
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.2.9200.20000" test_ref="oval:org.mitre.oval:tst:80697"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:18706" version="5" class="vulnerability">
      <metadata>
        <title>Information disclosure vulnerability in Microsoft Internet Explorer (CVE-2013-3908) - MS13-088</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2013-3908" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3908"/>
        <description>Microsoft Internet Explorer 6 through 10 allows user-assisted remote attackers to bypass the Same Origin Policy and obtain sensitive information from any visited document via a crafted web page that is not properly handled during a print-preview action, aka "Internet Explorer Information Disclosure Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2013-11-15T11:11:35">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-11-18T19:08:21.443-05:00">DRAFT</status_change>
            <status_change date="2013-12-09T04:00:09.210-05:00">INTERIM</status_change>
            <status_change date="2013-12-30T04:00:14.581-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:18706 - extended definitions of OS are without SP checks" date="2014-07-28T18:04:00.247-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T18:06:31.174-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:02:02.187-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="ie6">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="either os">
            <criteria operator="AND" comment="ie6 on win xp">
              <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
              <criterion comment="Check if the version of mshtml.dll is less than 6.0.2900.6462" test_ref="oval:org.mitre.oval:tst:86575"/>
            </criteria>
            <criteria operator="AND" comment="ie 6 on win xp 64 bit, server 2003 (32+64+ia64)">
              <criteria operator="OR" comment="either of the os">
                <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5238" test_ref="oval:org.mitre.oval:tst:87268"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="ie7">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="either os">
            <criteria operator="AND" comment="win xp/server 2003">
              <criteria operator="OR" comment="either os">
                <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
                <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21359" test_ref="oval:org.mitre.oval:tst:86325"/>
            </criteria>
            <criteria operator="AND" comment="vista/server 2008">
              <criteria operator="OR" comment="either os">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.18961" test_ref="oval:org.mitre.oval:tst:87153"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23244" test_ref="oval:org.mitre.oval:tst:86327"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="ie 8 on win xp/2003/vista/2008/win 7/2008 R2">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="either os">
            <criteria operator="AND" comment="win xp/server 2003">
              <criteria operator="OR" comment="either os">
                <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
                <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23536" test_ref="oval:org.mitre.oval:tst:87313"/>
            </criteria>
            <criteria operator="AND" comment="vista/server 2008">
              <criteria operator="OR" comment="either os">
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19483" test_ref="oval:org.mitre.oval:tst:87230"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23536" test_ref="oval:org.mitre.oval:tst:87313"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="win 7/server 2008 r2 and version">
              <criteria operator="OR" comment="win 7/server 2008 r2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18283" test_ref="oval:org.mitre.oval:tst:86870"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22479" test_ref="oval:org.mitre.oval:tst:87072"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="ie 9 on winvista/2008/win 7/2008 r2">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="win vista/2008/7/2008 r2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16520" test_ref="oval:org.mitre.oval:tst:86990"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20631" test_ref="oval:org.mitre.oval:tst:86626"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 and vulnerable file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7 / R2 / Win 8 / 2k12 and vulnerable file version">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16736" test_ref="oval:org.mitre.oval:tst:87036"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.20000" test_ref="oval:org.mitre.oval:tst:80523"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.20848" test_ref="oval:org.mitre.oval:tst:87041"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:18665" version="6" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability (CVE-2013-3893) - MS13-080</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2013-3893" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3893"/>
        <description>Use-after-free vulnerability in the SetMouseCapture implementation in mshtml.dll in Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code via crafted JavaScript strings, as demonstrated by use of an ms-help: URL that triggers loading of hxds.dll.</description>
        <oval_repository>
          <dates>
            <submitted date="2013-10-15T09:59:37">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-10-17T11:52:43.751-04:00">DRAFT</status_change>
            <status_change date="2013-11-04T04:00:57.755-05:00">INTERIM</status_change>
            <status_change date="2013-11-25T04:00:40.061-05:00">ACCEPTED</status_change>
            <status_change date="2013-11-25T04:00:25.617-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:18665 - extended definitions of OS are without SP checks" date="2014-07-28T18:03:00.291-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T18:04:48.108-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:02:01.658-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="ie6">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="either os">
            <criteria operator="AND" comment="ie6 on win xp">
              <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
              <criterion comment="Check if the version of mshtml.dll is less than 6.0.2900.6452" test_ref="oval:org.mitre.oval:tst:86820"/>
            </criteria>
            <criteria operator="AND" comment="ie 6 on win xp 64 bit, server 2003 (32+64+ia64)">
              <criteria operator="OR" comment="either of the os">
                <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5226" test_ref="oval:org.mitre.oval:tst:86832"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="ie7">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="either os">
            <criteria operator="AND" comment="win xp/server 2003">
              <criteria operator="OR" comment="either os">
                <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
                <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21357" test_ref="oval:org.mitre.oval:tst:86909"/>
            </criteria>
            <criteria operator="AND" comment="vista/server 2008">
              <criteria operator="OR" comment="either os">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.18945" test_ref="oval:org.mitre.oval:tst:86593"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23226" test_ref="oval:org.mitre.oval:tst:87007"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="ie 8 on win xp/2003/vista/2008/win 7/2008 R2">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="either os">
            <criteria operator="AND" comment="win xp/server 2003">
              <criteria operator="OR" comment="either os">
                <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
                <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23532" test_ref="oval:org.mitre.oval:tst:87046"/>
            </criteria>
            <criteria operator="AND" comment="vista/server 2008">
              <criteria operator="OR" comment="either os">
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19475" test_ref="oval:org.mitre.oval:tst:86894"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23532" test_ref="oval:org.mitre.oval:tst:87046"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="win 7/server 2008 r2 and version">
              <criteria operator="OR" comment="win 7/server 2008 r2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18269" test_ref="oval:org.mitre.oval:tst:86964"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22464" test_ref="oval:org.mitre.oval:tst:86867"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="ie 9 on winvista/2008/win 7/2008 r2">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="win vista/2008/7/2008 r2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16514" test_ref="oval:org.mitre.oval:tst:87018"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20625" test_ref="oval:org.mitre.oval:tst:86985"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 and vulnerable file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7 / R2 / Win 8 / 2k12 and vulnerable file version">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16721" test_ref="oval:org.mitre.oval:tst:86866"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.20000" test_ref="oval:org.mitre.oval:tst:80523"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.20831" test_ref="oval:org.mitre.oval:tst:87045"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:18660" version="3" class="vulnerability">
      <metadata>
        <title>Win32k Elevation of Privilege Vulnerability (CVE-2013-1341) - MS13-076</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2013-1341" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1341"/>
        <description>win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, and Windows 8 allows local users to gain privileges via a crafted application, aka "Win32k Multiple Fetch Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2013-09-13T17:32:25">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-09-17T09:58:56.326-04:00">DRAFT</status_change>
            <status_change date="2013-10-07T04:10:49.572-04:00">INTERIM</status_change>
            <status_change date="2013-10-28T04:00:20.427-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="XP x86">
          <criterion comment="Check if the version of Win32k.sys is less than 5.1.2600.6436" test_ref="oval:org.mitre.oval:tst:86748"/>
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
        </criteria>
        <criteria operator="AND" comment="XP/2K3 and vulnerable file version">
          <criteria operator="OR" comment="XP/2K3">
            <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
          </criteria>
          <criterion comment="Check if the version of Win32k.sys is less than 5.2.3790.5210" test_ref="oval:org.mitre.oval:tst:86056"/>
        </criteria>
        <criteria operator="AND" comment="Vista/2K8 and vulnerable file version">
          <criteria operator="OR" comment="Vista/2K8">
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
            <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of Win32k.sys is less than 6.0.6002.18912" test_ref="oval:org.mitre.oval:tst:86366"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is less than 6.0.6002.23185" test_ref="oval:org.mitre.oval:tst:86704"/>
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:81723"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="7/2K8 R2 and vulnerable file version">
          <criteria operator="OR" comment="7/2K8 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12292"/>
            <extend_definition comment="Microsoft Windows 7 x64 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12627"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12567"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12583"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of Win32k.sys is less than 6.1.7601.18233" test_ref="oval:org.mitre.oval:tst:86683"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is less than 6.1.7601.22416" test_ref="oval:org.mitre.oval:tst:86771"/>
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:81763"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="8/2k12 and vulnerable file version">
          <criteria operator="OR" comment="8/2k12">
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of Win32k.sys is less than 6.2.9200.16681" test_ref="oval:org.mitre.oval:tst:86515"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is less than 6.2.9200.20789" test_ref="oval:org.mitre.oval:tst:86732"/>
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.2.9200.20000" test_ref="oval:org.mitre.oval:tst:80697"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:18651" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability (CVE-2013-3201) - MS13-069</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Vista</platform>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2013-3201" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3201"/>
        <description>Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3203, CVE-2013-3206, CVE-2013-3207, and CVE-2013-3209.</description>
        <oval_repository>
          <dates>
            <submitted date="2013-09-13T17:32:25">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-09-17T09:45:59.822-04:00">DRAFT</status_change>
            <status_change date="2013-10-07T04:10:47.471-04:00">INTERIM</status_change>
            <status_change date="2013-10-28T04:00:19.751-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:18651 - extended definitions of OS are without SP checks" date="2014-07-28T18:01:00.642-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T18:03:07.317-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:02:01.452-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="ie 9 on winvista/2008/win 7/2008 r2">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="win vista/2008/7/2008 r2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16506" test_ref="oval:org.mitre.oval:tst:86531"/>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20617" test_ref="oval:org.mitre.oval:tst:85921"/>
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="ie 10 on win 7/2008 r2/win 8/server 2012">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="ie 10 on win 7/2008 r2/win 8/server 2012">
            <criteria operator="AND" comment="win 7/2008 r2 and version">
              <criteria operator="OR" comment="win 7/2008 r2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="gdr/ldr">
                <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16686" test_ref="oval:org.mitre.oval:tst:86004"/>
                <criteria operator="AND" comment="ldr range">
                  <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.20794" test_ref="oval:org.mitre.oval:tst:86689"/>
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.20000" test_ref="oval:org.mitre.oval:tst:80523"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="win 8/2012 and version">
              <criteria operator="OR" comment="win 8/2012">
                <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
                <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
                <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
              </criteria>
              <criteria operator="OR" comment="gdr/ldr">
                <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16688" test_ref="oval:org.mitre.oval:tst:86710"/>
                <criteria operator="AND" comment="ldr range">
                  <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.20796" test_ref="oval:org.mitre.oval:tst:86427"/>
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.20000" test_ref="oval:org.mitre.oval:tst:80523"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:18650" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability (CVE-2013-3209) - MS13-069</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Vista</platform>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2013-3209" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3209"/>
        <description>Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3201, CVE-2013-3203, CVE-2013-3206, and CVE-2013-3207.</description>
        <oval_repository>
          <dates>
            <submitted date="2013-09-13T17:32:25">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-09-17T09:45:15.909-04:00">DRAFT</status_change>
            <status_change date="2013-10-07T04:10:46.906-04:00">INTERIM</status_change>
            <status_change date="2013-10-28T04:00:19.040-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:18650 - extended definitions of OS are without SP checks" date="2014-07-28T18:01:00.642-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T18:03:05.275-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:02:01.241-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="ie 9 on winvista/2008/win 7/2008 r2">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="win vista/2008/7/2008 r2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16506" test_ref="oval:org.mitre.oval:tst:86531"/>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20617" test_ref="oval:org.mitre.oval:tst:85921"/>
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="ie 10 on win 7/2008 r2/win 8/server 2012">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="ie 10 on win 7/2008 r2/win 8/server 2012">
            <criteria operator="AND" comment="win 7/2008 r2 and version">
              <criteria operator="OR" comment="win 7/2008 r2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="gdr/ldr">
                <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16686" test_ref="oval:org.mitre.oval:tst:86004"/>
                <criteria operator="AND" comment="ldr range">
                  <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.20794" test_ref="oval:org.mitre.oval:tst:86689"/>
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.20000" test_ref="oval:org.mitre.oval:tst:80523"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="win 8/2012 and version">
              <criteria operator="OR" comment="win 8/2012">
                <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
                <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
                <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
              </criteria>
              <criteria operator="OR" comment="gdr/ldr">
                <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16688" test_ref="oval:org.mitre.oval:tst:86710"/>
                <criteria operator="AND" comment="ldr range">
                  <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.20796" test_ref="oval:org.mitre.oval:tst:86427"/>
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.20000" test_ref="oval:org.mitre.oval:tst:80523"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:18630" version="6" class="vulnerability">
      <metadata>
        <title>Windows USB Descriptor Vulnerability (CVE-2013-3200) - MS13-081</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2013-3200" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3200"/>
        <description>The USB drivers in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT allow physically proximate attackers to execute arbitrary code by connecting a crafted USB device, aka "Windows USB Descriptor Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2013-10-15T15:40:52">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-10-17T11:48:26.631-04:00">DRAFT</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:18630 - test oval:org.mitre.oval:tst:86769 is not apply to Windows 8 (64-bit) and Server 2012 (64-bit)." date="2013-11-01T13:13:00.269-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-11-18T04:00:08.428-05:00">INTERIM</status_change>
            <status_change date="2013-12-09T04:00:08.873-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:23627 - update for ms13-081, as per the revision V2.0 for kb2862330 to systems running Windows 7 and Windows Server 2008 R2" date="2014-02-06T12:30:00.673-05:00">
              <contributor organization="SecPod Technologies">Bhavya K</contributor>
            </modified>
            <status_change date="2014-02-06T12:32:02.041-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:24.560-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="xp sp3/version">
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <criteria operator="OR" comment="either file versions">
            <criterion comment="Check if the version of usbd.sys is less than 5.1.2600.6437" test_ref="oval:org.mitre.oval:tst:86755"/>
            <criterion comment="Check if the version of Hidparse.sys is less than 5.1.2600.6418" test_ref="oval:org.mitre.oval:tst:86930"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="win xp/server 2003/versions">
          <criteria operator="OR" comment="xp/server 2003">
            <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
          </criteria>
          <criteria operator="OR" comment="either file versions">
            <criterion comment="Check if the version of usbd.sys is less than 5.2.3790.5203" test_ref="oval:org.mitre.oval:tst:86911"/>
            <criterion comment="Check if the version of Hidparse.sys is less than 5.2.3790.5189" test_ref="oval:org.mitre.oval:tst:87022"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="vista/2008/version">
          <criteria operator="OR" comment="vista/2008">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
            <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
          </criteria>
          <criteria operator="OR" comment="either file versions">
            <criteria operator="OR" comment="gdr/ldr">
              <criterion comment="Check if the version of usbd.sys is less than 6.0.6002.18875" test_ref="oval:org.mitre.oval:tst:86418"/>
              <criteria operator="AND" comment="ldr range">
                <criterion comment="Check if the version of usbd.sys is less than 6.0.6002.23147" test_ref="oval:org.mitre.oval:tst:86514"/>
                <criterion comment="check if the version of usbd.sys is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:86977"/>
              </criteria>
            </criteria>
            <criteria operator="OR" comment="gdr/ldr">
              <criterion comment="Check if the version of Hidparse.sys is less than 6.0.6002.18878" test_ref="oval:org.mitre.oval:tst:86730"/>
              <criteria operator="AND" comment="ldr range">
                <criterion comment="Check if the version of Hidparse.sys is less than 6.0.6002.23150" test_ref="oval:org.mitre.oval:tst:86859"/>
                <criterion comment="Check if the version of Hidparse.sys is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:86640"/>
              </criteria>
            </criteria>
            <criteria operator="OR" comment="gdr/ldr">
              <criterion comment="Check if the version of Usbcir.sys is less than 6.0.6002.18887" test_ref="oval:org.mitre.oval:tst:86078"/>
              <criteria operator="AND" comment="ldr range">
                <criterion comment="Check if the version of Usbcir.sys is less than 6.0.6002.23160" test_ref="oval:org.mitre.oval:tst:86619"/>
                <criterion comment="Check if the version of Usbcir.sys is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:86822"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="win 7/2008 r2/versions">
          <criteria operator="OR" comment="win/2008 r2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12292"/>
            <extend_definition comment="Microsoft Windows 7 x64 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12627"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12567"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12583"/>
          </criteria>
          <criteria operator="OR" comment="either file versions">
            <criteria operator="OR" comment="gdr/ldr">
              <criterion comment="Check if the version of usbd.sys is less than 6.1.7601.18328" test_ref="oval:org.mitre.oval:tst:87035"/>
              <criteria operator="AND" comment="ldr range">
                <criterion comment="Check if the version of usbd.sys is less than 6.1.7601.22526" test_ref="oval:org.mitre.oval:tst:86925"/>
                <criterion comment="Check if the version of usbd.sys is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:86874"/>
              </criteria>
            </criteria>
            <criteria operator="OR" comment="gdr/ldr">
              <criterion comment="Check if the version of Hidparse.sys is less than 6.1.7601.18199" test_ref="oval:org.mitre.oval:tst:86880"/>
              <criteria operator="AND" comment="ldr range">
                <criterion comment="Check if the version of Hidparse.sys is less than 6.1.7601.22374" test_ref="oval:org.mitre.oval:tst:86872"/>
                <criterion comment="Check if the version of Hidparse.sys is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:86951"/>
              </criteria>
            </criteria>
            <criteria operator="OR" comment="gdr/ldr">
              <criterion comment="Check if the version of Usbcir.sys is less than 6.1.7601.18208" test_ref="oval:org.mitre.oval:tst:86981"/>
              <criteria operator="AND" comment="ldr range">
                <criterion comment="Check if the version of Usbcir.sys is less than 6.1.7601.22382" test_ref="oval:org.mitre.oval:tst:87012"/>
                <criterion comment="Check if the version of Usbcir.sys is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:86997"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="win 8/server 2012">
          <criteria operator="OR" comment="win 8/server 2012">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="either file versions">
            <criteria operator="OR" comment="gdr/ldr">
              <criterion comment="Check if the version of Hidparse.sys is less than 6.2.9200.16654" test_ref="oval:org.mitre.oval:tst:86804"/>
              <criteria operator="AND" comment="ldr range">
                <criterion comment="Check if the version of Hidparse.sys is less than 6.2.9200.20763" test_ref="oval:org.mitre.oval:tst:86846"/>
                <criterion comment="Check if the version of Hidparse.sys is greater than or equal to 6.2.9200.20000" test_ref="oval:org.mitre.oval:tst:86853"/>
              </criteria>
            </criteria>
            <criteria operator="OR" comment="gdr/ldr">
              <criterion comment="Check if the version of usbd.sys is less than 6.2.9200.16654" test_ref="oval:org.mitre.oval:tst:86624"/>
              <criteria operator="AND" comment="ldr range">
                <criterion comment="Check if the version of usbd.sys is less than 6.2.9200.20761" test_ref="oval:org.mitre.oval:tst:86747"/>
                <criterion comment="Check if the version of usbd.sys is greater than or equal to 6.2.9200.20000" test_ref="oval:org.mitre.oval:tst:86397"/>
              </criteria>
            </criteria>
            <criteria operator="OR" comment="gdr/ldr">
              <criterion comment="Check if the version of Usbxhci.sys is less than 6.2.9200.16654" test_ref="oval:org.mitre.oval:tst:86475"/>
              <criteria operator="AND" comment="ldr range">
                <criterion comment="Check if the version of Usbxhci.sys is less than 6.2.9200.20763" test_ref="oval:org.mitre.oval:tst:86663"/>
                <criterion comment="Check if the version of Usbxhci.sys is greater than or equal to 6.2.9200.20000" test_ref="oval:org.mitre.oval:tst:86783"/>
              </criteria>
            </criteria>
            <criterion comment="Check if the version of Wdfldr.sys is less than 1.11.9200.16648" test_ref="oval:org.mitre.oval:tst:87039"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="win 8/server 2012 x64">
          <criteria operator="OR" comment="win 8/server 2012">
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of Usbcir.sys is less than 6.2.9200.16658" test_ref="oval:org.mitre.oval:tst:86726"/>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of Usbcir.sys is less than 6.2.9200.20772" test_ref="oval:org.mitre.oval:tst:86645"/>
              <criterion comment="Check if the version of Usbcir.sys is greater than or equal to 6.2.9200.20000" test_ref="oval:org.mitre.oval:tst:86482"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="win 8 x86">
          <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of Usbcir.sys is less than 6.2.9200.16659" test_ref="oval:org.mitre.oval:tst:86769"/>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of Usbcir.sys is less than 6.2.9200.20772" test_ref="oval:org.mitre.oval:tst:86645"/>
              <criterion comment="Check if the version of Usbcir.sys is greater than or equal to 6.2.9200.20000" test_ref="oval:org.mitre.oval:tst:86482"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="vista/2008//win7/2008 r2 (32/64)/version">
          <criteria operator="OR" comment="vista/2008/win7/2008 r2 (32/64)">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12292"/>
            <extend_definition comment="Microsoft Windows 7 x64 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12627"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12567"/>
          </criteria>
          <criterion comment="Check if the version of Wdfldr.sys is less than 1.11.9200.16384" test_ref="oval:org.mitre.oval:tst:86803"/>
        </criteria>
        <criteria operator="AND" comment="server 2008 ia-64/version">
          <criteria operator="OR" comment="2008/r2">
            <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12583"/>
          </criteria>
          <criterion comment="Check if the version of Wdfldr.sys is less than 1.9.7600.16385" test_ref="oval:org.mitre.oval:tst:86962"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:18601" version="6" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability (CVE-2013-3872) - MS13-080</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <product>Microsoft Internet Explorer 10</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2013-3872" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3872"/>
        <description>Microsoft Internet Explorer 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3873, CVE-2013-3882, and CVE-2013-3885.</description>
        <oval_repository>
          <dates>
            <submitted date="2013-10-15T09:59:37">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-10-17T11:53:13.474-04:00">DRAFT</status_change>
            <status_change date="2013-11-04T04:00:53.220-05:00">INTERIM</status_change>
            <status_change date="2013-11-25T04:00:39.295-05:00">ACCEPTED</status_change>
            <status_change date="2013-11-25T04:00:25.005-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:18601 - extended definitions of OS are without SP checks" date="2014-07-28T18:03:00.291-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T18:04:50.091-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:02:01.026-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
        <criteria operator="OR" comment="Win 7 / R2 / Win 8 / 2k12 and vulnerable file version">
          <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
          <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
          <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
          <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
          <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
        </criteria>
        <criteria operator="OR" comment="Check for vulnerable version">
          <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16721" test_ref="oval:org.mitre.oval:tst:86866"/>
          <criteria operator="AND" comment="Check for LDR">
            <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.20000" test_ref="oval:org.mitre.oval:tst:80523"/>
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.20831" test_ref="oval:org.mitre.oval:tst:87045"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:18557" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability (CVE-2013-3202) - MS13-069</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <product>Microsoft Internet Explorer 10</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2013-3202" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3202"/>
        <description>Microsoft Internet Explorer 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2013-09-13T17:32:25">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-09-17T09:45:09.322-04:00">DRAFT</status_change>
            <status_change date="2013-10-07T04:10:30.006-04:00">INTERIM</status_change>
            <status_change date="2013-10-28T04:00:16.419-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:18557 - extended definitions of OS are without SP checks" date="2014-07-28T18:01:00.642-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T18:03:06.941-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:02:00.805-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
        <criteria operator="OR" comment="ie 10 on win 7/2008 r2/win 8/server 2012">
          <criteria operator="AND" comment="win 7/2008 r2 and version">
            <criteria operator="OR" comment="win 7/2008 r2">
              <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
              <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
              <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            </criteria>
            <criteria operator="OR" comment="gdr/ldr">
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16686" test_ref="oval:org.mitre.oval:tst:86004"/>
              <criteria operator="AND" comment="ldr range">
                <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.20794" test_ref="oval:org.mitre.oval:tst:86689"/>
                <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.20000" test_ref="oval:org.mitre.oval:tst:80523"/>
              </criteria>
            </criteria>
          </criteria>
          <criteria operator="AND" comment="win 8/2012 and version">
            <criteria operator="OR" comment="win 8/2012">
              <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
              <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
              <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
            </criteria>
            <criteria operator="OR" comment="gdr/ldr">
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16688" test_ref="oval:org.mitre.oval:tst:86710"/>
              <criteria operator="AND" comment="ldr range">
                <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.20796" test_ref="oval:org.mitre.oval:tst:86427"/>
                <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.20000" test_ref="oval:org.mitre.oval:tst:80523"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:18553" version="3" class="vulnerability">
      <metadata>
        <title>Win32k Elevation of Privilege Vulnerability (CVE-2013-3864) - MS13-076</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2013-3864" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3864"/>
        <description>win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT allows local users to gain privileges via a crafted application, aka "Win32k Multiple Fetch Vulnerability," a different vulnerability than CVE-2013-1342, CVE-2013-1343, CVE-2013-1344, and CVE-2013-3865.</description>
        <oval_repository>
          <dates>
            <submitted date="2013-09-13T17:32:25">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-09-17T09:58:46.580-04:00">DRAFT</status_change>
            <status_change date="2013-10-07T04:10:28.937-04:00">INTERIM</status_change>
            <status_change date="2013-10-28T04:00:15.702-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="XP x86">
          <criterion comment="Check if the version of Win32k.sys is less than 5.1.2600.6436" test_ref="oval:org.mitre.oval:tst:86748"/>
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
        </criteria>
        <criteria operator="AND" comment="XP/2K3 and vulnerable file version">
          <criteria operator="OR" comment="XP/2K3">
            <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
          </criteria>
          <criterion comment="Check if the version of Win32k.sys is less than 5.2.3790.5210" test_ref="oval:org.mitre.oval:tst:86056"/>
        </criteria>
        <criteria operator="AND" comment="Vista/2K8 and vulnerable file version">
          <criteria operator="OR" comment="Vista/2K8">
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
            <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of Win32k.sys is less than 6.0.6002.18912" test_ref="oval:org.mitre.oval:tst:86366"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is less than 6.0.6002.23185" test_ref="oval:org.mitre.oval:tst:86704"/>
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:81723"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="7/2K8 R2 and vulnerable file version">
          <criteria operator="OR" comment="7/2K8 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12292"/>
            <extend_definition comment="Microsoft Windows 7 x64 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12627"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12567"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12583"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of Win32k.sys is less than 6.1.7601.18233" test_ref="oval:org.mitre.oval:tst:86683"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is less than 6.1.7601.22416" test_ref="oval:org.mitre.oval:tst:86771"/>
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:81763"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="8/2k12 and vulnerable file version">
          <criteria operator="OR" comment="8/2k12">
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of Win32k.sys is less than 6.2.9200.16681" test_ref="oval:org.mitre.oval:tst:86515"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is less than 6.2.9200.20789" test_ref="oval:org.mitre.oval:tst:86732"/>
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.2.9200.20000" test_ref="oval:org.mitre.oval:tst:80697"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:18551" version="3" class="vulnerability">
      <metadata>
        <title>Win32k Elevation of Privilege Vulnerability (CVE-2013-1343) - MS13-076</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2013-1343" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1343"/>
        <description>win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT allows local users to gain privileges via a crafted application, aka "Win32k Multiple Fetch Vulnerability," a different vulnerability than CVE-2013-1342, CVE-2013-1344, CVE-2013-3864, and CVE-2013-3865.</description>
        <oval_repository>
          <dates>
            <submitted date="2013-09-13T17:32:25">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-09-17T09:59:15.750-04:00">DRAFT</status_change>
            <status_change date="2013-10-07T04:10:28.061-04:00">INTERIM</status_change>
            <status_change date="2013-10-28T04:00:14.899-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="XP x86">
          <criterion comment="Check if the version of Win32k.sys is less than 5.1.2600.6436" test_ref="oval:org.mitre.oval:tst:86748"/>
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
        </criteria>
        <criteria operator="AND" comment="XP/2K3 and vulnerable file version">
          <criteria operator="OR" comment="XP/2K3">
            <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
          </criteria>
          <criterion comment="Check if the version of Win32k.sys is less than 5.2.3790.5210" test_ref="oval:org.mitre.oval:tst:86056"/>
        </criteria>
        <criteria operator="AND" comment="Vista/2K8 and vulnerable file version">
          <criteria operator="OR" comment="Vista/2K8">
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
            <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of Win32k.sys is less than 6.0.6002.18912" test_ref="oval:org.mitre.oval:tst:86366"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is less than 6.0.6002.23185" test_ref="oval:org.mitre.oval:tst:86704"/>
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:81723"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="7/2K8 R2 and vulnerable file version">
          <criteria operator="OR" comment="7/2K8 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12292"/>
            <extend_definition comment="Microsoft Windows 7 x64 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12627"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12567"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12583"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of Win32k.sys is less than 6.1.7601.18233" test_ref="oval:org.mitre.oval:tst:86683"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is less than 6.1.7601.22416" test_ref="oval:org.mitre.oval:tst:86771"/>
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:81763"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="8/2k12 and vulnerable file version">
          <criteria operator="OR" comment="8/2k12">
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of Win32k.sys is less than 6.2.9200.16681" test_ref="oval:org.mitre.oval:tst:86515"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is less than 6.2.9200.20789" test_ref="oval:org.mitre.oval:tst:86732"/>
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.2.9200.20000" test_ref="oval:org.mitre.oval:tst:80697"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:18488" version="5" class="vulnerability">
      <metadata>
        <title>Memory corruption vulnerability in Microsoft Internet Explorer (CVE-2013-3916) - MS13-088</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2013-3916" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3916"/>
        <description>Microsoft Internet Explorer 8 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3912.</description>
        <oval_repository>
          <dates>
            <submitted date="2013-11-15T11:11:35">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-11-18T19:08:26.172-05:00">DRAFT</status_change>
            <status_change date="2013-12-09T04:00:08.472-05:00">INTERIM</status_change>
            <status_change date="2013-12-30T04:00:13.923-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:18488 - extended definitions of OS are without SP checks" date="2014-07-28T18:03:00.291-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T18:04:50.282-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:01:59.978-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="ie 8 on win xp/2003/vista/2008/win 7/2008 R2">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="either os">
            <criteria operator="AND" comment="win xp/server 2003">
              <criteria operator="OR" comment="either os">
                <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
                <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23536" test_ref="oval:org.mitre.oval:tst:87313"/>
            </criteria>
            <criteria operator="AND" comment="vista/server 2008">
              <criteria operator="OR" comment="either os">
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19483" test_ref="oval:org.mitre.oval:tst:87230"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23536" test_ref="oval:org.mitre.oval:tst:87313"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="win 7/server 2008 r2 and version">
              <criteria operator="OR" comment="win 7/server 2008 r2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18283" test_ref="oval:org.mitre.oval:tst:86870"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22479" test_ref="oval:org.mitre.oval:tst:87072"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="ie 9 on winvista/2008/win 7/2008 r2">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="win vista/2008/7/2008 r2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16520" test_ref="oval:org.mitre.oval:tst:86990"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20631" test_ref="oval:org.mitre.oval:tst:86626"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 and vulnerable file version">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7 / R2 / Win 8 / 2k12 and vulnerable file version">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16736" test_ref="oval:org.mitre.oval:tst:87036"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.20000" test_ref="oval:org.mitre.oval:tst:80523"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.20848" test_ref="oval:org.mitre.oval:tst:87041"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 11 and vulnerable file version">
          <extend_definition comment="Microsoft Internet Explorer 11 is installed" definition_ref="oval:org.mitre.oval:def:18343"/>
          <criteria operator="OR" comment="Win 8.1 / 2k12 R2 and vulnerable file version">
            <extend_definition comment="Microsoft Windows 8.1 is installed" definition_ref="oval:org.mitre.oval:def:18863"/>
            <extend_definition comment="Microsoft Windows Server 2012 R2 is installed" definition_ref="oval:org.mitre.oval:def:18858"/>
          </criteria>
          <criterion comment="Check if the version of mshtml.dll is less than 11.0.9431.224" test_ref="oval:org.mitre.oval:tst:87282"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:18863" version="3" class="inventory">
      <metadata>
        <title>Microsoft Windows 8.1 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 8.1</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/o:microsoft:windows_8:1"/>
        <description>The operating system installed on the system is Microsoft Windows 8.1</description>
        <oval_repository>
          <dates>
            <submitted date="2013-07-26T13:03:37">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </submitted>
            <status_change date="2013-09-17T17:10:30.444-04:00">DRAFT</status_change>
            <status_change date="2013-10-07T04:11:20.068-04:00">INTERIM</status_change>
            <status_change date="2013-10-28T04:00:37.515-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="the installed operating system is part of the Microsoft Windows family" test_ref="oval:org.mitre.oval:tst:99"/>
        <criterion comment="Windows 8.1 is installed" test_ref="oval:org.mitre.oval:tst:86924"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:18858" version="3" class="inventory">
      <metadata>
        <title>Microsoft Windows Server 2012 R2 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2012 R2</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/o:microsoft:windows_server_2012:r2"/>
        <description>The operating system installed on the system is Microsoft Windows Server 2012
          R2.</description>
        <oval_repository>
          <dates>
            <submitted date="2013-10-14T13:00:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </submitted>
            <status_change date="2013-10-17T12:01:31.566-04:00">DRAFT</status_change>
            <status_change date="2013-11-11T04:00:47.464-05:00">INTERIM</status_change>
            <status_change date="2013-11-26T13:49:13.957-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="the installed operating system is part of the Microsoft Windows family" test_ref="oval:org.mitre.oval:tst:99"/>
        <criterion comment="Check if Windows Server 2012 R2 is installed" test_ref="oval:org.mitre.oval:tst:87015"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:18343" version="7" class="inventory">
      <metadata>
        <title>Microsoft Internet Explorer 11 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 8.1</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012 R2</platform>
          <product>Microsoft Internet Explorer 11</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:ie:11"/>
        <description>Microsoft Internet Explorer 11 is installed</description>
        <oval_repository>
          <dates>
            <submitted date="2013-11-15T11:11:35">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-11-18T19:08:25.972-05:00">DRAFT</status_change>
            <status_change date="2013-12-09T04:00:08.269-05:00">INTERIM</status_change>
            <status_change date="2013-12-30T04:00:14.534-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:18343 - Updating platforms for Internet Explorer 11." date="2013-12-30T09:03:00.322-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-12-30T09:07:45.958-05:00">INTERIM</status_change>
            <status_change date="2014-01-20T04:00:17.922-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:23453 - Updated comment to include IE 11 given that this object is referenced by IE 11 inventory definitions." date="2014-12-05T18:57:00.896-05:00">
              <contributor organization="CIS">Blake Frantz</contributor>
            </modified>
            <status_change date="2014-12-05T18:59:51.501-05:00">INTERIM</status_change>
            <status_change date="2014-12-22T04:00:06.360-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="Check if Microsoft Internet Explorer 11 is installed" test_ref="oval:org.mitre.oval:tst:87142"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:18421" version="3" class="vulnerability">
      <metadata>
        <title>Windows Kernel Memory Corruption Vulnerability - MS13-063</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 7</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2013-3198" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3198"/>
        <description>The NT Virtual DOS Machine (NTVDM) subsystem in the kernel in Microsoft Windows XP SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, Windows 7 SP1, and Windows 8 on 32-bit platforms does not properly validate kernel-memory addresses, which allows local users to gain privileges or cause a denial of service (memory corruption) via a crafted application, aka "Windows Kernel Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3196 and CVE-2013-3197.</description>
        <oval_repository>
          <dates>
            <submitted date="2013-08-19T16:03:07">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-08-19T14:44:35.400-04:00">DRAFT</status_change>
            <status_change date="2013-09-09T04:03:38.201-04:00">INTERIM</status_change>
            <status_change date="2013-09-30T04:01:13.272-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="x86 XP and vulnerable file version">
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <criterion comment="Check if the version of Ntoskrnl.exe is less than 5.1.2600.6419" test_ref="oval:org.mitre.oval:tst:86154"/>
        </criteria>
        <criteria operator="AND" comment="x86 2003 and vulnerable file version">
          <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
          <criterion comment="Check if the version of Ntoskrnl.exe is less than 5.2.3790.5190" test_ref="oval:org.mitre.oval:tst:85984"/>
        </criteria>
        <criteria operator="AND" comment="Vista/2008 and vulnerable file version">
          <criteria operator="OR" comment="Vista/2008">
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of Ntoskrnl.exe is less than 6.0.6002.18881" test_ref="oval:org.mitre.oval:tst:85206"/>
            <criteria operator="AND" comment="Check for LDR range">
              <criterion comment="Check if the version of Ntoskrnl.exe is less than 6.0.6002.23154" test_ref="oval:org.mitre.oval:tst:85647"/>
              <criterion comment="Check if the version of Ntoskrnl.exe is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80719"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="7 and vulnerable file version">
          <extend_definition comment="Microsoft Windows 7 (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12292"/>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of Ntoskrnl.exe is less than 6.1.7601.18205" test_ref="oval:org.mitre.oval:tst:85401"/>
            <criteria operator="AND" comment="Check for LDR range">
              <criterion comment="Check if the version of Ntoskrnl.exe is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:81000"/>
              <criterion comment="Check if the version of Ntoskrnl.exe is less than 6.1.7601.22379" test_ref="oval:org.mitre.oval:tst:85600"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="8 and vulnerable file version">
          <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of Ntoskrnl.exe is less than 6.2.9200.16659" test_ref="oval:org.mitre.oval:tst:85833"/>
            <criteria operator="AND" comment="Check for LDR range">
              <criterion comment="Check if the version of Ntoskrnl.exe is less than 6.2.9200.20772" test_ref="oval:org.mitre.oval:tst:85877"/>
              <criterion comment="Check if the version of Ntoskrnl.exe is greater than or equal to 6.2.9200.20000" test_ref="oval:org.mitre.oval:tst:80722"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:18366" version="6" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability (CVE-2013-3882) - MS13-080</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <product>Microsoft Internet Explorer 10</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2013-3882" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3882"/>
        <description>Microsoft Internet Explorer 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3872, CVE-2013-3873, and CVE-2013-3885.</description>
        <oval_repository>
          <dates>
            <submitted date="2013-10-15T09:59:37">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-10-17T11:52:48.070-04:00">DRAFT</status_change>
            <status_change date="2013-11-04T04:00:46.486-05:00">INTERIM</status_change>
            <status_change date="2013-11-25T04:00:36.362-05:00">ACCEPTED</status_change>
            <status_change date="2013-11-25T04:00:23.485-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:18366 - extended definitions of OS are without SP checks" date="2014-07-28T18:03:00.291-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T18:04:45.512-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:01:59.814-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
        <criteria operator="OR" comment="Win 7 / R2 / Win 8 / 2k12 and vulnerable file version">
          <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
          <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
          <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
          <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
          <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
        </criteria>
        <criteria operator="OR" comment="Check for vulnerable version">
          <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16721" test_ref="oval:org.mitre.oval:tst:86866"/>
          <criteria operator="AND" comment="Check for LDR">
            <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.20000" test_ref="oval:org.mitre.oval:tst:80523"/>
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.20831" test_ref="oval:org.mitre.oval:tst:87045"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:18364" version="3" class="vulnerability">
      <metadata>
        <title>Windows Kernel Memory Corruption Vulnerability - MS13-063</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 7</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2013-3197" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3197"/>
        <description>The NT Virtual DOS Machine (NTVDM) subsystem in the kernel in Microsoft Windows XP SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, Windows 7 SP1, and Windows 8 on 32-bit platforms does not properly validate kernel-memory addresses, which allows local users to gain privileges or cause a denial of service (memory corruption) via a crafted application, aka "Windows Kernel Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3196 and CVE-2013-3198.</description>
        <oval_repository>
          <dates>
            <submitted date="2013-08-19T16:03:07">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-08-19T14:44:29.913-04:00">DRAFT</status_change>
            <status_change date="2013-09-09T04:03:33.175-04:00">INTERIM</status_change>
            <status_change date="2013-09-30T04:01:07.890-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="x86 XP and vulnerable file version">
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <criterion comment="Check if the version of Ntoskrnl.exe is less than 5.1.2600.6419" test_ref="oval:org.mitre.oval:tst:86154"/>
        </criteria>
        <criteria operator="AND" comment="x86 2003 and vulnerable file version">
          <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
          <criterion comment="Check if the version of Ntoskrnl.exe is less than 5.2.3790.5190" test_ref="oval:org.mitre.oval:tst:85984"/>
        </criteria>
        <criteria operator="AND" comment="Vista/2008 and vulnerable file version">
          <criteria operator="OR" comment="Vista/2008">
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of Ntoskrnl.exe is less than 6.0.6002.18881" test_ref="oval:org.mitre.oval:tst:85206"/>
            <criteria operator="AND" comment="Check for LDR range">
              <criterion comment="Check if the version of Ntoskrnl.exe is less than 6.0.6002.23154" test_ref="oval:org.mitre.oval:tst:85647"/>
              <criterion comment="Check if the version of Ntoskrnl.exe is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80719"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="7 and vulnerable file version">
          <extend_definition comment="Microsoft Windows 7 (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12292"/>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of Ntoskrnl.exe is less than 6.1.7601.18205" test_ref="oval:org.mitre.oval:tst:85401"/>
            <criteria operator="AND" comment="Check for LDR range">
              <criterion comment="Check if the version of Ntoskrnl.exe is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:81000"/>
              <criterion comment="Check if the version of Ntoskrnl.exe is less than 6.1.7601.22379" test_ref="oval:org.mitre.oval:tst:85600"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="8 and vulnerable file version">
          <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of Ntoskrnl.exe is less than 6.2.9200.16659" test_ref="oval:org.mitre.oval:tst:85833"/>
            <criteria operator="AND" comment="Check for LDR range">
              <criterion comment="Check if the version of Ntoskrnl.exe is less than 6.2.9200.20772" test_ref="oval:org.mitre.oval:tst:85877"/>
              <criterion comment="Check if the version of Ntoskrnl.exe is greater than or equal to 6.2.9200.20000" test_ref="oval:org.mitre.oval:tst:80722"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:18293" version="5" class="vulnerability">
      <metadata>
        <title>Remote Procedure Call Vulnerability - MS13-062</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2013-3175" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3175"/>
        <description>Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT allow remote attackers to execute arbitrary code via a malformed asynchronous RPC request, aka "Remote Procedure Call Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2013-08-19T11:06:57">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-08-19T14:42:45.219-04:00">DRAFT</status_change>
            <status_change date="2013-09-09T04:03:25.148-04:00">INTERIM</status_change>
            <status_change date="2013-09-30T04:01:02.266-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:5160 - contains tests with modified comments and all dependences" date="2014-02-13T12:19:00.287-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-13T12:23:04.387-05:00">INTERIM</status_change>
            <status_change date="2014-03-03T04:00:58.606-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="XP X86 SP3 and vulnerable file version">
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <criterion comment="Check if the version of rpcrt4.dll is less than 5.1.2600.6399" test_ref="oval:org.mitre.oval:tst:86117"/>
        </criteria>
        <criteria operator="AND" comment="XP X64 / 2K3 all _+ vulnerable file version">
          <criteria operator="OR" comment="XP X64 / 2K3">
            <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
          </criteria>
          <criterion comment="Check if the version of rpcrt4.dll is less than 5.2.3790.5194" test_ref="oval:org.mitre.oval:tst:86012"/>
        </criteria>
        <criteria operator="AND" comment="Vista / 2K8 and vulnerable file version">
          <criteria operator="OR" comment="Vista / 2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
            <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of rpcrt4.dll is less than 6.0.6002.18882" test_ref="oval:org.mitre.oval:tst:85836"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="the version of rpcrt4.dll is greater than 6.0.6002.22000" test_ref="oval:org.mitre.oval:tst:10194"/>
              <criterion comment="Check if the version of rpcrt4.dll is less than 6.0.6002.23155" test_ref="oval:org.mitre.oval:tst:86082"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / R2 and vulnerable file version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12292"/>
            <extend_definition comment="Microsoft Windows 7 x64 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12627"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12567"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12583"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of rpcrt4.dll is less than 6.1.7601.18205" test_ref="oval:org.mitre.oval:tst:86045"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of rpcrt4.dll is greater than or equal 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:85227"/>
              <criterion comment="Check if the version of rpcrt4.dll is less than 6.1.7601.23155" test_ref="oval:org.mitre.oval:tst:86040"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8 / 2012 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2012 and vulnerable file version">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of rpcrt4.dll is less than 6.2.9200.16622" test_ref="oval:org.mitre.oval:tst:86124"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of rpcrt4.dll is greater than or equal 6.2.9200.20000" test_ref="oval:org.mitre.oval:tst:86115"/>
              <criterion comment="Check if the version of rpcrt4.dll is less than 6.2.9200.20727" test_ref="oval:org.mitre.oval:tst:86121"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:18271" version="5" class="vulnerability">
      <metadata>
        <title>Memory corruption vulnerability in Internet Explorer - CVE-2013-3184  MS13-059</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2013-3184" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3184"/>
        <description>Microsoft Internet Explorer 7 through 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2013-08-19T11:12:04">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-08-19T14:37:44.101-04:00">DRAFT</status_change>
            <status_change date="2013-09-09T04:03:23.132-04:00">INTERIM</status_change>
            <status_change date="2013-09-30T04:01:00.002-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:18271 - extended definitions of OS are without SP checks" date="2014-07-28T18:01:00.642-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T18:03:11.210-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:01:59.043-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="ie7">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="either os">
            <criteria operator="AND" comment="win xp/server 2003">
              <criteria operator="OR" comment="either os">
                <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
                <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
                <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21348" test_ref="oval:org.mitre.oval:tst:85969"/>
            </criteria>
            <criteria operator="AND" comment="vista/server 2008">
              <criteria operator="OR" comment="either os">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="gdr/ldr">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.18891" test_ref="oval:org.mitre.oval:tst:86081"/>
                <criteria operator="AND" comment="ldr range">
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23164" test_ref="oval:org.mitre.oval:tst:86142"/>
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="ie 8 on win xp/2003/vista/2008/win 7/2008 R2">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="either os">
            <criteria operator="AND" comment="win xp/server 2003">
              <criteria operator="OR" comment="either os">
                <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
                <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23515" test_ref="oval:org.mitre.oval:tst:85822"/>
            </criteria>
            <criteria operator="AND" comment="vista/server 2008">
              <criteria operator="OR" comment="either os">
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
              </criteria>
              <criteria operator="OR" comment="gdr/ldr">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19453" test_ref="oval:org.mitre.oval:tst:85575"/>
                <criteria operator="AND" comment="ldr range">
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23515" test_ref="oval:org.mitre.oval:tst:85822"/>
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="win 7/server 2008 r2">
              <criteria operator="OR" comment="either os">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="gdr.ldr">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18210" test_ref="oval:org.mitre.oval:tst:86106"/>
                <criteria operator="AND" comment="ldr range">
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22389" test_ref="oval:org.mitre.oval:tst:86155"/>
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="ie 9 on winvista/2008/win 7/2008 r2">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16502" test_ref="oval:org.mitre.oval:tst:85755"/>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20613" test_ref="oval:org.mitre.oval:tst:86120"/>
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="ie 10 on win 7/2008 r2/win 8/server 2012">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16660" test_ref="oval:org.mitre.oval:tst:85917"/>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.20768" test_ref="oval:org.mitre.oval:tst:86072"/>
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.20000" test_ref="oval:org.mitre.oval:tst:80523"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:18269" version="5" class="vulnerability">
      <metadata>
        <title>Memory corruption vulnerability in Internet Explorer - CVE-2013-3191  MS13-059</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Vista</platform>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2013-3191" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3191"/>
        <description>Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3187 and CVE-2013-3193.</description>
        <oval_repository>
          <dates>
            <submitted date="2013-08-19T11:12:04">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-08-19T14:37:51.297-04:00">DRAFT</status_change>
            <status_change date="2013-09-09T04:03:22.464-04:00">INTERIM</status_change>
            <status_change date="2013-09-30T04:00:59.431-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:18269 - extended definitions of OS are without SP checks" date="2014-07-28T18:01:00.642-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T18:03:07.599-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:01:58.823-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="ie 9 on winvista/2008/win 7/2008 r2">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16502" test_ref="oval:org.mitre.oval:tst:85755"/>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20613" test_ref="oval:org.mitre.oval:tst:86120"/>
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="ie 10 on win 7/2008 r2/win 8/server 2012">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16660" test_ref="oval:org.mitre.oval:tst:85917"/>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.20768" test_ref="oval:org.mitre.oval:tst:86072"/>
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.20000" test_ref="oval:org.mitre.oval:tst:80523"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:18203" version="5" class="vulnerability">
      <metadata>
        <title>Memory corruption vulnerability in Internet Explorer - CVE-2013-3199  MS13-059</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2013-3199" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3199"/>
        <description>Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2013-08-19T11:12:04">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-08-19T14:36:27.910-04:00">DRAFT</status_change>
            <status_change date="2013-09-09T04:03:16.936-04:00">INTERIM</status_change>
            <status_change date="2013-09-30T04:00:54.507-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:18203 - extended definitions of OS are without SP checks" date="2014-07-28T18:01:00.642-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T18:03:02.831-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:01:58.348-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="ie6">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="either os">
            <criteria operator="AND" comment="ie6 on win xp">
              <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
              <criterion comment="Check if the version of mshtml.dll is less than 6.0.2900.6425" test_ref="oval:org.mitre.oval:tst:86129"/>
            </criteria>
            <criteria operator="AND" comment="ie 6 on win xp 64 bit, server 2003 (32+64+ia64)">
              <criteria operator="OR" comment="either of the os">
                <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
                <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5198" test_ref="oval:org.mitre.oval:tst:86107"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="ie7">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="either os">
            <criteria operator="AND" comment="win xp/server 2003">
              <criteria operator="OR" comment="either os">
                <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
                <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
                <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21348" test_ref="oval:org.mitre.oval:tst:85969"/>
            </criteria>
            <criteria operator="AND" comment="vista/server 2008">
              <criteria operator="OR" comment="either os">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="gdr/ldr">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.18891" test_ref="oval:org.mitre.oval:tst:86081"/>
                <criteria operator="AND" comment="ldr range">
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23164" test_ref="oval:org.mitre.oval:tst:86142"/>
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="ie 8 on win xp/2003/vista/2008/win 7/2008 R2">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="either os">
            <criteria operator="AND" comment="win xp/server 2003">
              <criteria operator="OR" comment="either os">
                <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
                <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23515" test_ref="oval:org.mitre.oval:tst:85822"/>
            </criteria>
            <criteria operator="AND" comment="vista/server 2008">
              <criteria operator="OR" comment="either os">
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
              </criteria>
              <criteria operator="OR" comment="gdr/ldr">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19453" test_ref="oval:org.mitre.oval:tst:85575"/>
                <criteria operator="AND" comment="ldr range">
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23515" test_ref="oval:org.mitre.oval:tst:85822"/>
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="win 7/server 2008 r2">
              <criteria operator="OR" comment="either os">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="gdr.ldr">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18210" test_ref="oval:org.mitre.oval:tst:86106"/>
                <criteria operator="AND" comment="ldr range">
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22389" test_ref="oval:org.mitre.oval:tst:86155"/>
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="ie 9 on winvista/2008/win 7/2008 r2">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16502" test_ref="oval:org.mitre.oval:tst:85755"/>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20613" test_ref="oval:org.mitre.oval:tst:86120"/>
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="ie 10 on win 7/2008 r2/win 8/server 2012">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16660" test_ref="oval:org.mitre.oval:tst:85917"/>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.20768" test_ref="oval:org.mitre.oval:tst:86072"/>
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.20000" test_ref="oval:org.mitre.oval:tst:80523"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:18175" version="3" class="vulnerability">
      <metadata>
        <title>Windows Kernel Memory Corruption Vulnerability - MS13-063</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 7</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2013-3196" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3196"/>
        <description>The NT Virtual DOS Machine (NTVDM) subsystem in the kernel in Microsoft Windows XP SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, Windows 7 SP1, and Windows 8 on 32-bit platforms does not properly validate kernel-memory addresses, which allows local users to gain privileges or cause a denial of service (memory corruption) via a crafted application, aka "Windows Kernel Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3197 and CVE-2013-3198.</description>
        <oval_repository>
          <dates>
            <submitted date="2013-08-19T16:03:07">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-08-19T14:44:40.196-04:00">DRAFT</status_change>
            <status_change date="2013-09-09T04:03:15.398-04:00">INTERIM</status_change>
            <status_change date="2013-09-30T04:00:52.985-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="x86 XP and vulnerable file version">
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <criterion comment="Check if the version of Ntoskrnl.exe is less than 5.1.2600.6419" test_ref="oval:org.mitre.oval:tst:86154"/>
        </criteria>
        <criteria operator="AND" comment="x86 2003 and vulnerable file version">
          <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
          <criterion comment="Check if the version of Ntoskrnl.exe is less than 5.2.3790.5190" test_ref="oval:org.mitre.oval:tst:85984"/>
        </criteria>
        <criteria operator="AND" comment="Vista/2008 and vulnerable file version">
          <criteria operator="OR" comment="Vista/2008">
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of Ntoskrnl.exe is less than 6.0.6002.18881" test_ref="oval:org.mitre.oval:tst:85206"/>
            <criteria operator="AND" comment="Check for LDR range">
              <criterion comment="Check if the version of Ntoskrnl.exe is less than 6.0.6002.23154" test_ref="oval:org.mitre.oval:tst:85647"/>
              <criterion comment="Check if the version of Ntoskrnl.exe is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80719"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="7 and vulnerable file version">
          <extend_definition comment="Microsoft Windows 7 (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12292"/>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of Ntoskrnl.exe is less than 6.1.7601.18205" test_ref="oval:org.mitre.oval:tst:85401"/>
            <criteria operator="AND" comment="Check for LDR range">
              <criterion comment="Check if the version of Ntoskrnl.exe is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:81000"/>
              <criterion comment="Check if the version of Ntoskrnl.exe is less than 6.1.7601.22379" test_ref="oval:org.mitre.oval:tst:85600"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="8 and vulnerable file version">
          <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of Ntoskrnl.exe is less than 6.2.9200.16659" test_ref="oval:org.mitre.oval:tst:85833"/>
            <criteria operator="AND" comment="Check for LDR range">
              <criterion comment="Check if the version of Ntoskrnl.exe is less than 6.2.9200.20772" test_ref="oval:org.mitre.oval:tst:85877"/>
              <criterion comment="Check if the version of Ntoskrnl.exe is greater than or equal to 6.2.9200.20000" test_ref="oval:org.mitre.oval:tst:80722"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:18137" version="5" class="vulnerability">
      <metadata>
        <title>Memory corruption vulnerability in Internet Explorer - CVE-2013-3187  MS13-059</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Vista</platform>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2013-3187" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3187"/>
        <description>Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3191 and CVE-2013-3193.</description>
        <oval_repository>
          <dates>
            <submitted date="2013-08-19T11:12:04">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-08-19T14:37:32.079-04:00">DRAFT</status_change>
            <status_change date="2013-09-09T04:03:14.774-04:00">INTERIM</status_change>
            <status_change date="2013-09-30T04:00:52.429-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:18137 - extended definitions of OS are without SP checks" date="2014-07-28T18:01:00.642-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T18:03:08.545-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:01:58.060-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="ie 9 on winvista/2008/win 7/2008 r2">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16502" test_ref="oval:org.mitre.oval:tst:85755"/>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20613" test_ref="oval:org.mitre.oval:tst:86120"/>
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="ie 10 on win 7/2008 r2/win 8/server 2012">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16660" test_ref="oval:org.mitre.oval:tst:85917"/>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.20768" test_ref="oval:org.mitre.oval:tst:86072"/>
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.20000" test_ref="oval:org.mitre.oval:tst:80523"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:18114" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability (CVE-2013-3208) - MS13-069</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2013-3208" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3208"/>
        <description>Microsoft Internet Explorer 8 through 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2013-09-13T17:32:25">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-09-17T09:46:10.862-04:00">DRAFT</status_change>
            <status_change date="2013-10-07T04:09:42.321-04:00">INTERIM</status_change>
            <status_change date="2013-10-28T04:00:07.369-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:18114 - extended definitions of OS are without SP checks" date="2014-07-28T18:01:00.642-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T18:03:03.674-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:01:57.571-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="ie 8 on win xp/2003/vista/2008/win 7/2008 R2">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="either os">
            <criteria operator="AND" comment="win xp/server 2003">
              <criteria operator="OR" comment="either os">
                <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
                <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23520" test_ref="oval:org.mitre.oval:tst:86705"/>
            </criteria>
            <criteria operator="AND" comment="vista/server 2008">
              <criteria operator="OR" comment="either os">
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
              </criteria>
              <criteria operator="OR" comment="gdr/ldr">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19458" test_ref="oval:org.mitre.oval:tst:86484"/>
                <criteria operator="AND" comment="ldr range">
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23520" test_ref="oval:org.mitre.oval:tst:86705"/>
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="win 7/server 2008 r2 and version">
              <criteria operator="OR" comment="win 7/server 2008 r2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="gdr/ldr">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18228" test_ref="oval:org.mitre.oval:tst:86192"/>
                <criteria operator="AND" comment="ldr range">
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22410" test_ref="oval:org.mitre.oval:tst:85906"/>
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="ie 9 on winvista/2008/win 7/2008 r2">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="win vista/2008/7/2008 r2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16506" test_ref="oval:org.mitre.oval:tst:86531"/>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20617" test_ref="oval:org.mitre.oval:tst:85921"/>
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="ie 10 on win 7/2008 r2/win 8/server 2012">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="ie 10 on win 7/2008 r2/win 8/server 2012">
            <criteria operator="AND" comment="win 7/2008 r2 and version">
              <criteria operator="OR" comment="win 7/2008 r2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="gdr/ldr">
                <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16686" test_ref="oval:org.mitre.oval:tst:86004"/>
                <criteria operator="AND" comment="ldr range">
                  <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.20794" test_ref="oval:org.mitre.oval:tst:86689"/>
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.20000" test_ref="oval:org.mitre.oval:tst:80523"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="win 8/2012 and version">
              <criteria operator="OR" comment="win 8/2012">
                <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
                <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
                <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
              </criteria>
              <criteria operator="OR" comment="gdr/ldr">
                <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16688" test_ref="oval:org.mitre.oval:tst:86710"/>
                <criteria operator="AND" comment="ldr range">
                  <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.20796" test_ref="oval:org.mitre.oval:tst:86427"/>
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.20000" test_ref="oval:org.mitre.oval:tst:80523"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:18037" version="5" class="vulnerability">
      <metadata>
        <title>Memory corruption vulnerability in Internet Explorer - CVE-2013-3190  MS13-059</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2013-3190" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3190"/>
        <description>Microsoft Internet Explorer 8 through 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2013-08-19T11:12:04">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-08-19T14:37:06.736-04:00">DRAFT</status_change>
            <status_change date="2013-09-09T04:03:11.814-04:00">INTERIM</status_change>
            <status_change date="2013-09-30T04:00:49.848-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:18037 - extended definitions of OS are without SP checks" date="2014-07-28T18:01:00.642-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T18:03:06.686-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:01:57.333-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="ie 8 on win xp/2003/vista/2008/win 7/2008 R2">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="either os">
            <criteria operator="AND" comment="win xp/server 2003">
              <criteria operator="OR" comment="either os">
                <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
                <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23515" test_ref="oval:org.mitre.oval:tst:85822"/>
            </criteria>
            <criteria operator="AND" comment="vista/server 2008">
              <criteria operator="OR" comment="either os">
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
              </criteria>
              <criteria operator="OR" comment="gdr/ldr">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19453" test_ref="oval:org.mitre.oval:tst:85575"/>
                <criteria operator="AND" comment="ldr range">
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23515" test_ref="oval:org.mitre.oval:tst:85822"/>
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="win 7/server 2008 r2">
              <criteria operator="OR" comment="either os">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="gdr.ldr">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18210" test_ref="oval:org.mitre.oval:tst:86106"/>
                <criteria operator="AND" comment="ldr range">
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22389" test_ref="oval:org.mitre.oval:tst:86155"/>
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="ie 9 on winvista/2008/win 7/2008 r2">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16502" test_ref="oval:org.mitre.oval:tst:85755"/>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20613" test_ref="oval:org.mitre.oval:tst:86120"/>
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="ie 10 on win 7/2008 r2/win 8/server 2012">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16660" test_ref="oval:org.mitre.oval:tst:85917"/>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.20768" test_ref="oval:org.mitre.oval:tst:86072"/>
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.20000" test_ref="oval:org.mitre.oval:tst:80523"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:18031" version="6" class="vulnerability">
      <metadata>
        <title>Elevation of privilege vulnerability in Internet Explorer - CVE-2013-3186  MS13-059</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Vista</platform>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2013-3186" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3186"/>
        <description>The Protected Mode feature in Microsoft Internet Explorer 7 through 10 on Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT does not properly implement the Integrity Access Level (aka IL) protection mechanism, which allows remote attackers to obtain medium-integrity privileges by leveraging access to a low-integrity process, aka "Process Integrity Level Assignment Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2013-08-19T11:12:04">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-08-19T14:36:51.290-04:00">DRAFT</status_change>
            <status_change date="2013-09-09T04:03:10.303-04:00">INTERIM</status_change>
            <status_change date="2013-09-30T04:00:48.693-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:18031 - extended definitions of OS are without SP checks" date="2014-07-28T18:01:00.642-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T18:03:09.536-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:01:57.062-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="ie7">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.18891" test_ref="oval:org.mitre.oval:tst:86081"/>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23164" test_ref="oval:org.mitre.oval:tst:86142"/>
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="ie 8 on win xp/2003/vista/2008/win 7/2008 R2">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19453" test_ref="oval:org.mitre.oval:tst:85575"/>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23515" test_ref="oval:org.mitre.oval:tst:85822"/>
              <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="win 7/server 2008 r2">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="gdr.ldr">
            <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18210" test_ref="oval:org.mitre.oval:tst:86106"/>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22389" test_ref="oval:org.mitre.oval:tst:86155"/>
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="ie 9 on winvista/2008/win 7/2008 r2">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16502" test_ref="oval:org.mitre.oval:tst:85755"/>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20613" test_ref="oval:org.mitre.oval:tst:86120"/>
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="ie 10 on win 7/2008 r2/win 8/server 2012">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16660" test_ref="oval:org.mitre.oval:tst:85917"/>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.20768" test_ref="oval:org.mitre.oval:tst:86072"/>
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.20000" test_ref="oval:org.mitre.oval:tst:80523"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:17996" version="5" class="vulnerability">
      <metadata>
        <title>Memory corruption vulnerability in Internet Explorer - CVE-2013-3193  MS13-059</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2013-3193" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3193"/>
        <description>Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3187 and CVE-2013-3191.</description>
        <oval_repository>
          <dates>
            <submitted date="2013-08-19T11:12:04">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-08-19T14:36:14.845-04:00">DRAFT</status_change>
            <status_change date="2013-09-09T04:03:06.933-04:00">INTERIM</status_change>
            <status_change date="2013-09-30T04:00:46.616-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:17996 - extended definitions of OS are without SP checks" date="2014-07-28T18:01:00.642-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T18:03:08.056-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:01:56.821-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="ie 9 on winvista/2008/win 7/2008 r2">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16502" test_ref="oval:org.mitre.oval:tst:85755"/>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20613" test_ref="oval:org.mitre.oval:tst:86120"/>
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="ie 10 on win 7/2008 r2/win 8/server 2012">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16660" test_ref="oval:org.mitre.oval:tst:85917"/>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.20768" test_ref="oval:org.mitre.oval:tst:86072"/>
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.20000" test_ref="oval:org.mitre.oval:tst:80523"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:17980" version="5" class="vulnerability">
      <metadata>
        <title>Cross-site-scripting (XSS) vulnerability in Internet Explorer - CVE-2013-3192  MS13-059</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2013-3192" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3192"/>
        <description>Cross-site scripting (XSS) vulnerability in Microsoft Internet Explorer 6 through 10 allows remote attackers to inject arbitrary web script or HTML via crafted character sequences with EUC-JP encoding, aka "EUC-JP Character Encoding Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2013-08-19T11:12:04">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-08-19T14:36:40.841-04:00">DRAFT</status_change>
            <status_change date="2013-09-09T04:03:05.708-04:00">INTERIM</status_change>
            <status_change date="2013-09-30T04:00:45.637-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:17980 - extended definitions of OS are without SP checks" date="2014-07-28T18:01:00.642-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T18:03:10.944-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:01:56.492-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="ie6">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="either os">
            <criteria operator="AND" comment="ie6 on win xp">
              <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
              <criterion comment="Check if the version of mshtml.dll is less than 6.0.2900.6425" test_ref="oval:org.mitre.oval:tst:86129"/>
            </criteria>
            <criteria operator="AND" comment="ie 6 on win xp 64 bit, server 2003 (32+64+ia64)">
              <criteria operator="OR" comment="either of the os">
                <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
                <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5198" test_ref="oval:org.mitre.oval:tst:86107"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="ie7">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="either os">
            <criteria operator="AND" comment="win xp/server 2003">
              <criteria operator="OR" comment="either os">
                <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
                <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
                <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21348" test_ref="oval:org.mitre.oval:tst:85969"/>
            </criteria>
            <criteria operator="AND" comment="vista/server 2008">
              <criteria operator="OR" comment="either os">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="gdr/ldr">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.18891" test_ref="oval:org.mitre.oval:tst:86081"/>
                <criteria operator="AND" comment="ldr range">
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23164" test_ref="oval:org.mitre.oval:tst:86142"/>
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="ie 8 on win xp/2003/vista/2008/win 7/2008 R2">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="either os">
            <criteria operator="AND" comment="win xp/server 2003">
              <criteria operator="OR" comment="either os">
                <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
                <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23515" test_ref="oval:org.mitre.oval:tst:85822"/>
            </criteria>
            <criteria operator="AND" comment="vista/server 2008">
              <criteria operator="OR" comment="either os">
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
              </criteria>
              <criteria operator="OR" comment="gdr/ldr">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19453" test_ref="oval:org.mitre.oval:tst:85575"/>
                <criteria operator="AND" comment="ldr range">
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23515" test_ref="oval:org.mitre.oval:tst:85822"/>
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="win 7/server 2008 r2">
              <criteria operator="OR" comment="either os">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="gdr.ldr">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18210" test_ref="oval:org.mitre.oval:tst:86106"/>
                <criteria operator="AND" comment="ldr range">
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22389" test_ref="oval:org.mitre.oval:tst:86155"/>
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="ie 9 on winvista/2008/win 7/2008 r2">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16502" test_ref="oval:org.mitre.oval:tst:85755"/>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20613" test_ref="oval:org.mitre.oval:tst:86120"/>
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="ie 10 on win 7/2008 r2/win 8/server 2012">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16660" test_ref="oval:org.mitre.oval:tst:85917"/>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.20768" test_ref="oval:org.mitre.oval:tst:86072"/>
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.20000" test_ref="oval:org.mitre.oval:tst:80523"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:17918" version="3" class="vulnerability">
      <metadata>
        <title>Vulnerability in ICMPv6 could allow Denial of Service - MS13-065</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Vista</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2013-3183" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3183"/>
        <description>The TCP/IP implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT does not properly perform memory allocation for inbound ICMPv6 packets, which allows remote attackers to cause a denial of service (system hang) via crafted packets, aka "ICMPv6 Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2013-08-19T15:41:45">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-08-19T14:48:27.808-04:00">DRAFT</status_change>
            <status_change date="2013-09-09T04:03:02.821-04:00">INTERIM</status_change>
            <status_change date="2013-09-30T04:00:43.429-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Windows Vista / Server 2008 and vulnerable file version">
          <criteria operator="OR" comment="Win Vista/ Server 2008">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
            <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of tcpip.sys is less than 6.0.6002.18880" test_ref="oval:org.mitre.oval:tst:86002"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="the version of Tcpip.sys is greater than or equal 6.0.6002.22000" test_ref="oval:org.mitre.oval:tst:10619"/>
              <criterion comment="Check if the version of tcpip.sys is less than 6.0.6002.23152" test_ref="oval:org.mitre.oval:tst:86058"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Windows 7 / 2008 R2 and vulnerable file versions">
          <criteria operator="OR" comment="Windows 7 / 2008 R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12292"/>
            <extend_definition comment="Microsoft Windows 7 x64 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12627"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12567"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12583"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of tcpip.sys is less than 6.1.7601.18203" test_ref="oval:org.mitre.oval:tst:85901"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of tcpip.sys is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:81171"/>
              <criterion comment="Check if the version of tcpip.sys is less than 6.1.7601.22378" test_ref="oval:org.mitre.oval:tst:85684"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8 / 2012 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2012">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of tcpip.sys is less than 6.2.9200.16659" test_ref="oval:org.mitre.oval:tst:86123"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of tcpip.sys is greater than or equal to 6.2.9200.20000" test_ref="oval:org.mitre.oval:tst:80315"/>
              <criterion comment="Check if the version of tcpip.sys is less than 6.2.9200.20767" test_ref="oval:org.mitre.oval:tst:85463"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:17430" version="8" class="vulnerability">
      <metadata>
        <title>Delegate reflection bypass vulnerability in Microsoft .NET Framework - MS13-052</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft .NET Framework 1.1</product>
          <product>Microsoft .NET Framework 2.0</product>
          <product>Microsoft .NET Framework 3.5</product>
          <product>Microsoft .NET Framework 3.5.1</product>
          <product>Microsoft .NET Framework 4.0</product>
          <product>Microsoft .NET Framework 4.5</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2013-3132" ref_url="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2013-3132"/>
        <description>Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.5, 3.5.1, 4, and 4.5 does not properly check the permissions of objects that use reflection, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (XBAP) or (2) a crafted .NET Framework application, aka "Delegate Reflection Bypass Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2013-07-15T10:59:59">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-07-17T16:01:46.985-04:00">DRAFT</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:81826 - obj:15823 replaced obj:2009 because .net 4 is testing" date="2013-07-19T08:44:00.954-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-08-05T04:01:04.339-04:00">INTERIM</status_change>
            <status_change date="2013-08-26T04:00:32.517-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:17430 - .NET Framework 3.5.1 instead .NET Framework 3.5 in Windows 8 and Windows Server 2012" date="2014-03-31T14:51:00.481-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-03-31T14:53:45.311-04:00">INTERIM</status_change>
            <status_change date="2014-04-21T04:00:18.835-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:17430 - extended definitions of OS are without SP checks" date="2014-07-28T18:01:00.642-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T18:03:05.974-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:01:55.907-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment=".net 1.1 sp1/versions">
          <extend_definition comment="Microsoft .NET Framework 1.1 Service Pack 1 is Installed" definition_ref="oval:org.mitre.oval:def:1834"/>
          <criterion comment="Check if the version of mscorlib.dll is less than 1.1.4322.2503" test_ref="oval:org.mitre.oval:tst:81839"/>
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment=".net 2.0 sp2/xp/server 2003/versions">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 2.0 Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6158"/>
          <criteria operator="OR" comment="either file versions GDR/LDR">
            <criterion comment="Check if the version of mscorlib.dll is less than 2.0.50727.3649" test_ref="oval:org.mitre.oval:tst:81523"/>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of mscorlib.dll is less than 2.0.50727.7026" test_ref="oval:org.mitre.oval:tst:81025"/>
              <criterion comment="Check if the version of mscorlib.dll is greater than or equal to 2.0.50727.7000" test_ref="oval:org.mitre.oval:tst:80994"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment=".net 2.0 sp2/vista/server 2008/versions">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 2.0 Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6158"/>
          <criteria operator="OR" comment="either file versions">
            <criterion comment="Check if the version of mscorlib.dll is less than 2.0.50727.4241" test_ref="oval:org.mitre.oval:tst:80941"/>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of mscorlib.dll is less than 2.0.50727.7025" test_ref="oval:org.mitre.oval:tst:81880"/>
              <criterion comment="Check if the version of mscorlib.dll is greater than or equal to 2.0.50727.7000" test_ref="oval:org.mitre.oval:tst:80994"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment=".net 3.5/win8/server 2012/versions">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 3.5 SP1 is installed" definition_ref="oval:org.mitre.oval:def:12542"/>
          <criteria operator="OR" comment="either file versions">
            <criterion comment="Check if the version of mscorlib.dll is less than 2.0.50727.6407" test_ref="oval:org.mitre.oval:tst:81653"/>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of mscorlib.dll is less than 2.0.50727.7025" test_ref="oval:org.mitre.oval:tst:81880"/>
              <criterion comment="Check if the version of mscorlib.dll is greater than or equal to 2.0.50727.7000" test_ref="oval:org.mitre.oval:tst:80994"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment=".net 3.5.1/win 7/server 2008 R2/versions">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 3.5 SP1 is installed" definition_ref="oval:org.mitre.oval:def:12542"/>
          <criteria operator="OR" comment="either file versions">
            <criterion comment="Check if the version of mscorlib.dll is less than 2.0.50727.5472" test_ref="oval:org.mitre.oval:tst:81766"/>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of mscorlib.dll is less than 2.0.50727.7025" test_ref="oval:org.mitre.oval:tst:81880"/>
              <criterion comment="Check if the version of mscorlib.dll is greater than or equal to 2.0.50727.7000" test_ref="oval:org.mitre.oval:tst:80994"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment=".net 4.0/win xp.server 2003/vista/server 2008/win 7/server 2008 R2/versions">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6749"/>
          <criteria operator="OR" comment="either file versions">
            <criterion comment="Check if the version of mscorlib.dll is less than 4.0.30319.1008" test_ref="oval:org.mitre.oval:tst:81442"/>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of mscorlib.dll is less than 4.0.30319.2012" test_ref="oval:org.mitre.oval:tst:81826"/>
              <criterion comment="Check if the version of mscorlib.dll is greater than or equal to 4.0.30319.2000" test_ref="oval:org.mitre.oval:tst:81701"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment=".net 4.5/vista/server 2008/win 7/server 2008 R2/versions">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 4.5 is installed" definition_ref="oval:org.mitre.oval:def:15925"/>
          <criteria operator="OR" comment="either file versions">
            <criterion comment="Check if the version of mscorlib.dll is less than 4.0.30319.18052" test_ref="oval:org.mitre.oval:tst:81273"/>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of mscorlib.dll is less than 4.0.30319.19080" test_ref="oval:org.mitre.oval:tst:81487"/>
              <criterion comment="Check if the version of mscorlib.dll is greater than or equal to 4.0.30319.19000" test_ref="oval:org.mitre.oval:tst:80125"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment=".net 4.5/win 8/server 2012/versions">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 4.5 is installed" definition_ref="oval:org.mitre.oval:def:15925"/>
          <criteria operator="OR" comment="either file versions">
            <criterion comment="Check if the version of mscorlib.dll is less than 4.0.30319.18051" test_ref="oval:org.mitre.oval:tst:81655"/>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of mscorlib.dll is less than 4.0.30319.19079" test_ref="oval:org.mitre.oval:tst:81054"/>
              <criterion comment="Check if the version of mscorlib.dll is greater than or equal to 4.0.30319.19000" test_ref="oval:org.mitre.oval:tst:80125"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:17421" version="8" class="vulnerability">
      <metadata>
        <title>Anonymous method injection vulnerability in Microsoft .NET Framework - MS13-052</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft .NET Framework 2.0</product>
          <product>Microsoft .NET Framework 3.5</product>
          <product>Microsoft .NET Framework 3.5.1</product>
          <product>Microsoft .NET Framework 4.0</product>
          <product>Microsoft .NET Framework 4.5</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2013-3133" ref_url="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2013-3133"/>
        <description>Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, and 4.5 does not properly check the permissions of objects that use reflection, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (XBAP) or (2) a crafted .NET Framework application, aka "Anonymous Method Injection Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2013-07-15T10:59:59">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-07-17T16:01:46.048-04:00">DRAFT</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:81826 - obj:15823 replaced obj:2009 because .net 4 is testing" date="2013-07-19T08:44:00.954-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-08-05T04:01:02.947-04:00">INTERIM</status_change>
            <status_change date="2013-08-26T04:00:31.249-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:17421 - .NET Framework 3.5.1 instead .NET Framework 3.5 in Windows 8 and Windows Server 2012" date="2014-03-31T14:51:00.481-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-03-31T14:53:47.971-04:00">INTERIM</status_change>
            <status_change date="2014-04-21T04:00:18.328-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:17421 - extended definitions of OS are without SP checks" date="2014-07-28T18:01:00.642-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T18:03:09.870-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:01:55.527-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment=".net 2.0 sp2/xp/server 2003/versions">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 2.0 Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6158"/>
          <criteria operator="OR" comment="either file versions GDR/LDR">
            <criterion comment="Check if the version of mscorlib.dll is less than 2.0.50727.3649" test_ref="oval:org.mitre.oval:tst:81523"/>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of mscorlib.dll is less than 2.0.50727.7026" test_ref="oval:org.mitre.oval:tst:81025"/>
              <criterion comment="Check if the version of mscorlib.dll is greater than or equal to 2.0.50727.7000" test_ref="oval:org.mitre.oval:tst:80994"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment=".net 2.0 sp2/vista/server 2008/versions">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 2.0 Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6158"/>
          <criteria operator="OR" comment="either file versions">
            <criterion comment="Check if the version of mscorlib.dll is less than 2.0.50727.4241" test_ref="oval:org.mitre.oval:tst:80941"/>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of mscorlib.dll is less than 2.0.50727.7025" test_ref="oval:org.mitre.oval:tst:81880"/>
              <criterion comment="Check if the version of mscorlib.dll is greater than or equal to 2.0.50727.7000" test_ref="oval:org.mitre.oval:tst:80994"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment=".net 3.5/win8/server 2012/versions">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 3.5 SP1 is installed" definition_ref="oval:org.mitre.oval:def:12542"/>
          <criteria operator="OR" comment="either file versions">
            <criterion comment="Check if the version of mscorlib.dll is less than 2.0.50727.6407" test_ref="oval:org.mitre.oval:tst:81653"/>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of mscorlib.dll is less than 2.0.50727.7025" test_ref="oval:org.mitre.oval:tst:81880"/>
              <criterion comment="Check if the version of mscorlib.dll is greater than or equal to 2.0.50727.7000" test_ref="oval:org.mitre.oval:tst:80994"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment=".net 3.5.1/win 7/server 2008 R2/versions">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 3.5 SP1 is installed" definition_ref="oval:org.mitre.oval:def:12542"/>
          <criteria operator="OR" comment="either file versions">
            <criterion comment="Check if the version of mscorlib.dll is less than 2.0.50727.5472" test_ref="oval:org.mitre.oval:tst:81766"/>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of mscorlib.dll is less than 2.0.50727.7025" test_ref="oval:org.mitre.oval:tst:81880"/>
              <criterion comment="Check if the version of mscorlib.dll is greater than or equal to 2.0.50727.7000" test_ref="oval:org.mitre.oval:tst:80994"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment=".net 4.0/win xp.server 2003/vista/server 2008/win 7/server 2008 R2/versions">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6749"/>
          <criteria operator="OR" comment="either file versions">
            <criterion comment="Check if the version of mscorlib.dll is less than 4.0.30319.1008" test_ref="oval:org.mitre.oval:tst:81442"/>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of mscorlib.dll is less than 4.0.30319.2012" test_ref="oval:org.mitre.oval:tst:81826"/>
              <criterion comment="Check if the version of mscorlib.dll is greater than or equal to 4.0.30319.2000" test_ref="oval:org.mitre.oval:tst:81701"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment=".net 4.5/vista/server 2008/win 7/server 2008 R2/versions">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 4.5 is installed" definition_ref="oval:org.mitre.oval:def:15925"/>
          <criteria operator="OR" comment="either file versions">
            <criterion comment="Check if the version of mscorlib.dll is less than 4.0.30319.18052" test_ref="oval:org.mitre.oval:tst:81273"/>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of mscorlib.dll is less than 4.0.30319.19080" test_ref="oval:org.mitre.oval:tst:81487"/>
              <criterion comment="Check if the version of mscorlib.dll is greater than or equal to 4.0.30319.19000" test_ref="oval:org.mitre.oval:tst:80125"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment=".net 4.5/win 8/server 2012/versions">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 4.5 is installed" definition_ref="oval:org.mitre.oval:def:15925"/>
          <criteria operator="OR" comment="either file versions">
            <criterion comment="Check if the version of mscorlib.dll is less than 4.0.30319.18051" test_ref="oval:org.mitre.oval:tst:81655"/>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of mscorlib.dll is less than 4.0.30319.19079" test_ref="oval:org.mitre.oval:tst:81054"/>
              <criterion comment="Check if the version of mscorlib.dll is greater than or equal to 4.0.30319.19000" test_ref="oval:org.mitre.oval:tst:80125"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:17379" version="3" class="vulnerability">
      <metadata>
        <title>Win32k Vulnerability - CVE-2013-1345 (MS13-053)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 7</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2013-1345" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1345"/>
        <description>win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT does not properly handle objects in memory, which allows local users to gain privileges via a crafted application, aka "Win32k Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2013-07-15T19:34:20">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-07-17T16:02:02.892-04:00">DRAFT</status_change>
            <status_change date="2013-08-05T04:01:01.677-04:00">INTERIM</status_change>
            <status_change date="2013-08-26T04:00:29.587-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="XP x86">
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <criterion comment="Check if the version of Win32k.sys is less than 5.1.2600.6404" test_ref="oval:org.mitre.oval:tst:81903"/>
        </criteria>
        <criteria operator="AND" comment="XP/2K3 and vulnerable file version">
          <criteria operator="OR" comment="XP/2K3">
            <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
          </criteria>
          <criterion comment="Check if the version of Win32k.sys is less than 5.2.3790.5174" test_ref="oval:org.mitre.oval:tst:81786"/>
        </criteria>
        <criteria operator="AND" comment="Vista/2K8 and vulnerable file version">
          <criteria operator="OR" comment="Vista/2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
            <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of Win32k.sys is less than 6.0.6002.18861" test_ref="oval:org.mitre.oval:tst:81696"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is less than 6.0.6002.23132" test_ref="oval:org.mitre.oval:tst:81776"/>
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:81723"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="7/2K8 R2 and vulnerable file version">
          <criteria operator="OR" comment="7/2K8 R2">
            <extend_definition comment="Microsoft Windows 7 x64 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12627"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12292"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12583"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12567"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of Win32k.sys is less than 6.1.7601.18176" test_ref="oval:org.mitre.oval:tst:81882"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is less than 6.1.7601.22348" test_ref="oval:org.mitre.oval:tst:81601"/>
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:81763"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="8/2k12 and vulnerable file version">
          <criteria operator="OR" comment="8/2k12">
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of Win32k.sys is less than 6.2.9200.16627" test_ref="oval:org.mitre.oval:tst:81241"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is less than 6.2.9200.20732" test_ref="oval:org.mitre.oval:tst:81822"/>
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.2.9200.20000" test_ref="oval:org.mitre.oval:tst:80697"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:17363" version="5" class="vulnerability">
      <metadata>
        <title>Memory corruption vulnerability in Internet Explorer - CVE-2013-3163 (MS13-055)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2013-3163" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3163"/>
        <description>Microsoft Internet Explorer 8 through 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3144 and CVE-2013-3151.</description>
        <oval_repository>
          <dates>
            <submitted date="2013-07-12T12:43:10">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-07-12T16:13:26.372-04:00">DRAFT</status_change>
            <status_change date="2013-07-29T04:01:27.852-04:00">INTERIM</status_change>
            <status_change date="2013-08-19T04:03:53.907-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:17363 - extended definitions of OS are without SP checks" date="2014-07-28T17:59:00.295-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T18:01:20.716-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:01:55.061-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 8 + Win XP/2K3/Vista/2K8/Win7/R2 + vulnerable file versions">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="Check for vulnerable OS and respective file versions">
            <criteria operator="AND" comment="XP/2K3 and vulnerable file versions">
              <criteria operator="OR" comment="XP / 2K3">
                <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
                <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23507" test_ref="oval:org.mitre.oval:tst:81827"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2K8 and vulnerable file versions">
              <criteria operator="OR" comment="Vista / 2K8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19443" test_ref="oval:org.mitre.oval:tst:81789"/>
                <criteria operator="AND" comment="Check for LDR range">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23507" test_ref="oval:org.mitre.oval:tst:81827"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18170" test_ref="oval:org.mitre.oval:tst:81431"/>
                <criteria operator="AND" comment="Check for LDR range">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22341" test_ref="oval:org.mitre.oval:tst:81329"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + Win 7/R2/Vista/2K8 + vulnerable file versions">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="Vista/2K8/Win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16496" test_ref="oval:org.mitre.oval:tst:81875"/>
            <criteria operator="AND" comment="Check for LDR range">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20606" test_ref="oval:org.mitre.oval:tst:81808"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + Win 7/R2/Win8/2k12 + vulnerable file versions">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16635" test_ref="oval:org.mitre.oval:tst:81840"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.20000" test_ref="oval:org.mitre.oval:tst:80523"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.20742" test_ref="oval:org.mitre.oval:tst:81835"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:17360" version="3" class="vulnerability">
      <metadata>
        <title>Win32k Read AV Vulnerability - CVE-2013-3660 (MS13-053)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 7</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2013-3660" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3660"/>
        <description>The EPATHOBJ::pprFlattenRec function in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, and Windows Server 2012 does not properly initialize a pointer for the next object in a certain list, which allows local users to obtain write access to the PATHRECORD chain, and consequently gain privileges, by triggering excessive consumption of paged memory and then making many FlattenPath function calls, aka "Win32k Read AV Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2013-07-15T19:34:20">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-07-17T16:02:05.241-04:00">DRAFT</status_change>
            <status_change date="2013-08-05T04:01:00.792-04:00">INTERIM</status_change>
            <status_change date="2013-08-26T04:00:28.729-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="XP x86">
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <criterion comment="Check if the version of Win32k.sys is less than 5.1.2600.6404" test_ref="oval:org.mitre.oval:tst:81903"/>
        </criteria>
        <criteria operator="AND" comment="XP/2K3 and vulnerable file version">
          <criteria operator="OR" comment="XP/2K3">
            <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
          </criteria>
          <criterion comment="Check if the version of Win32k.sys is less than 5.2.3790.5174" test_ref="oval:org.mitre.oval:tst:81786"/>
        </criteria>
        <criteria operator="AND" comment="Vista/2K8 and vulnerable file version">
          <criteria operator="OR" comment="Vista/2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
            <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of Win32k.sys is less than 6.0.6002.18861" test_ref="oval:org.mitre.oval:tst:81696"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is less than 6.0.6002.23132" test_ref="oval:org.mitre.oval:tst:81776"/>
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:81723"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="7/2K8 R2 and vulnerable file version">
          <criteria operator="OR" comment="7/2K8 R2">
            <extend_definition comment="Microsoft Windows 7 x64 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12627"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12292"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12583"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12567"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of Win32k.sys is less than 6.1.7601.18176" test_ref="oval:org.mitre.oval:tst:81882"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is less than 6.1.7601.22348" test_ref="oval:org.mitre.oval:tst:81601"/>
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:81763"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="8/2k12 and vulnerable file version">
          <criteria operator="OR" comment="8/2k12">
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of Win32k.sys is less than 6.2.9200.16627" test_ref="oval:org.mitre.oval:tst:81241"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is less than 6.2.9200.20732" test_ref="oval:org.mitre.oval:tst:81822"/>
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.2.9200.20000" test_ref="oval:org.mitre.oval:tst:80697"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:17353" version="3" class="vulnerability">
      <metadata>
        <title>Win32k Memory Allocation Vulnerability- CVE-2013-1300 (MS13-053)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 7</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2013-1300" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1300"/>
        <description>win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT does not properly handle objects in memory, which allows local users to gain privileges via a crafted application, aka "Win32k Memory Allocation Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2013-07-15T19:34:20">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-07-17T16:02:01.584-04:00">DRAFT</status_change>
            <status_change date="2013-08-05T04:00:59.987-04:00">INTERIM</status_change>
            <status_change date="2013-08-26T04:00:27.553-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="XP x86">
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <criterion comment="Check if the version of Win32k.sys is less than 5.1.2600.6404" test_ref="oval:org.mitre.oval:tst:81903"/>
        </criteria>
        <criteria operator="AND" comment="XP/2K3 and vulnerable file version">
          <criteria operator="OR" comment="XP/2K3">
            <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
          </criteria>
          <criterion comment="Check if the version of Win32k.sys is less than 5.2.3790.5174" test_ref="oval:org.mitre.oval:tst:81786"/>
        </criteria>
        <criteria operator="AND" comment="Vista/2K8 and vulnerable file version">
          <criteria operator="OR" comment="Vista/2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
            <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of Win32k.sys is less than 6.0.6002.18861" test_ref="oval:org.mitre.oval:tst:81696"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is less than 6.0.6002.23132" test_ref="oval:org.mitre.oval:tst:81776"/>
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:81723"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="7/2K8 R2 and vulnerable file version">
          <criteria operator="OR" comment="7/2K8 R2">
            <extend_definition comment="Microsoft Windows 7 x64 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12627"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12292"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12583"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12567"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of Win32k.sys is less than 6.1.7601.18176" test_ref="oval:org.mitre.oval:tst:81882"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is less than 6.1.7601.22348" test_ref="oval:org.mitre.oval:tst:81601"/>
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:81763"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="8/2k12 and vulnerable file version">
          <criteria operator="OR" comment="8/2k12">
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of Win32k.sys is less than 6.2.9200.16627" test_ref="oval:org.mitre.oval:tst:81241"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is less than 6.2.9200.20732" test_ref="oval:org.mitre.oval:tst:81822"/>
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.2.9200.20000" test_ref="oval:org.mitre.oval:tst:80697"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:17306" version="5" class="vulnerability">
      <metadata>
        <title>Cross-site scripting vulnerability in Internet Explorer - CVE-2013-3166 (MS13-055)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2013-3166" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3166"/>
        <description>Cross-site scripting (XSS) vulnerability in Microsoft Internet Explorer 6 through 10 allows remote attackers to inject arbitrary web script or HTML via vectors involving incorrect auto-selection of the Shift JIS encoding, leading to cross-domain scrolling events, aka "Shift JIS Character Encoding Vulnerability," a different vulnerability than CVE-2013-0015.</description>
        <oval_repository>
          <dates>
            <submitted date="2013-07-12T12:43:10">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-07-12T16:13:27.491-04:00">DRAFT</status_change>
            <status_change date="2013-07-29T04:01:26.563-04:00">INTERIM</status_change>
            <status_change date="2013-08-19T04:03:39.562-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:17306 - extended definitions of OS are without SP checks" date="2014-07-28T17:59:00.295-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T18:01:23.027-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:01:54.713-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + Win XP/2K3 + vulnerable file versions">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="Check for vulnerable OS and respective file versions">
            <criteria operator="AND" comment="XP X86 and vulnerable file version">
              <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
              <criterion comment="Check if the version of mshtml.dll is less than 6.0.2900.6400" test_ref="oval:org.mitre.oval:tst:81844"/>
            </criteria>
            <criteria operator="AND" comment="XP X64 / 2K3 and vulnerable file version">
              <criteria operator="OR" comment="XP X64 / 2K3">
                <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5170" test_ref="oval:org.mitre.oval:tst:81724"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 7 + Win XP/2K3/Vista/2K8 + vulnerable file versions">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="Check for vulnerable OS and respective file versions">
            <criteria operator="AND" comment="XP/2K3 and vulnerable file versions">
              <criteria operator="OR" comment="XP / 2K3">
                <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
                <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21342" test_ref="oval:org.mitre.oval:tst:81752"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2K8 and vulnerable file versions">
              <criteria operator="OR" comment="Vista / 2K8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.18861" test_ref="oval:org.mitre.oval:tst:81698"/>
                <criteria operator="AND" comment="Check for LDR range">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23133" test_ref="oval:org.mitre.oval:tst:81717"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + Win XP/2K3/Vista/2K8/Win7/R2 + vulnerable file versions">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="Check for vulnerable OS and respective file versions">
            <criteria operator="AND" comment="XP/2K3 and vulnerable file versions">
              <criteria operator="OR" comment="XP / 2K3">
                <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
                <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23507" test_ref="oval:org.mitre.oval:tst:81827"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2K8 and vulnerable file versions">
              <criteria operator="OR" comment="Vista / 2K8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19443" test_ref="oval:org.mitre.oval:tst:81789"/>
                <criteria operator="AND" comment="Check for LDR range">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23507" test_ref="oval:org.mitre.oval:tst:81827"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18170" test_ref="oval:org.mitre.oval:tst:81431"/>
                <criteria operator="AND" comment="Check for LDR range">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22341" test_ref="oval:org.mitre.oval:tst:81329"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + Win 7/R2/Vista/2K8 + vulnerable file versions">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="Vista/2K8/Win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16496" test_ref="oval:org.mitre.oval:tst:81875"/>
            <criteria operator="AND" comment="Check for LDR range">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20606" test_ref="oval:org.mitre.oval:tst:81808"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + Win 7/R2/Win8/2k12 + vulnerable file versions">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16635" test_ref="oval:org.mitre.oval:tst:81840"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.20000" test_ref="oval:org.mitre.oval:tst:80523"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.20742" test_ref="oval:org.mitre.oval:tst:81835"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:17301" version="5" class="vulnerability">
      <metadata>
        <title>Memory corruption vulnerability in Internet Explorer - CVE-2013-3161 (MS13-055)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Vista</platform>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2013-3161" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3161"/>
        <description>Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3143.</description>
        <oval_repository>
          <dates>
            <submitted date="2013-07-12T12:43:10">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-07-12T16:13:23.969-04:00">DRAFT</status_change>
            <status_change date="2013-07-29T04:01:26.000-04:00">INTERIM</status_change>
            <status_change date="2013-08-19T04:03:37.347-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:17301 - extended definitions of OS are without SP checks" date="2014-07-28T17:59:00.295-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T18:01:23.596-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:01:54.529-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 9 + Win 7/R2/Vista/2K8 + vulnerable file versions">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="Vista/2K8/Win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16496" test_ref="oval:org.mitre.oval:tst:81875"/>
            <criteria operator="AND" comment="Check for LDR range">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20606" test_ref="oval:org.mitre.oval:tst:81808"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + Win 7/R2/Win8/2k12 + vulnerable file versions">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16635" test_ref="oval:org.mitre.oval:tst:81840"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.20000" test_ref="oval:org.mitre.oval:tst:80523"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.20742" test_ref="oval:org.mitre.oval:tst:81835"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:17273" version="3" class="vulnerability">
      <metadata>
        <title>Win32k Dereference Vulnerability - CVE-2013-1340 (MS13-053)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 7</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2013-1340" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1340"/>
        <description>win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT does not properly handle objects in memory, which allows local users to gain privileges via a crafted application, aka "Win32k Dereference Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2013-07-15T19:34:20">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-07-17T16:02:02.335-04:00">DRAFT</status_change>
            <status_change date="2013-08-05T04:00:52.953-04:00">INTERIM</status_change>
            <status_change date="2013-08-26T04:00:21.584-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="XP x86">
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <criterion comment="Check if the version of Win32k.sys is less than 5.1.2600.6404" test_ref="oval:org.mitre.oval:tst:81903"/>
        </criteria>
        <criteria operator="AND" comment="XP/2K3 and vulnerable file version">
          <criteria operator="OR" comment="XP/2K3">
            <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
          </criteria>
          <criterion comment="Check if the version of Win32k.sys is less than 5.2.3790.5174" test_ref="oval:org.mitre.oval:tst:81786"/>
        </criteria>
        <criteria operator="AND" comment="Vista/2K8 and vulnerable file version">
          <criteria operator="OR" comment="Vista/2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
            <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of Win32k.sys is less than 6.0.6002.18861" test_ref="oval:org.mitre.oval:tst:81696"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is less than 6.0.6002.23132" test_ref="oval:org.mitre.oval:tst:81776"/>
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:81723"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="7/2K8 R2 and vulnerable file version">
          <criteria operator="OR" comment="7/2K8 R2">
            <extend_definition comment="Microsoft Windows 7 x64 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12627"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12292"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12583"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12567"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of Win32k.sys is less than 6.1.7601.18176" test_ref="oval:org.mitre.oval:tst:81882"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is less than 6.1.7601.22348" test_ref="oval:org.mitre.oval:tst:81601"/>
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:81763"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="8/2k12 and vulnerable file version">
          <criteria operator="OR" comment="8/2k12">
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of Win32k.sys is less than 6.2.9200.16627" test_ref="oval:org.mitre.oval:tst:81241"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is less than 6.2.9200.20732" test_ref="oval:org.mitre.oval:tst:81822"/>
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.2.9200.20000" test_ref="oval:org.mitre.oval:tst:80697"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:17259" version="5" class="vulnerability">
      <metadata>
        <title>Memory corruption vulnerability in Internet Explorer - CVE-2013-3143 (MS13-055)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Vista</platform>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2013-3143" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3143"/>
        <description>Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3161.</description>
        <oval_repository>
          <dates>
            <submitted date="2013-07-12T12:43:10">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-07-12T16:13:17.623-04:00">DRAFT</status_change>
            <status_change date="2013-07-29T04:01:24.211-04:00">INTERIM</status_change>
            <status_change date="2013-08-19T04:03:25.688-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:17259 - extended definitions of OS are without SP checks" date="2014-07-28T17:59:00.295-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T18:01:21.292-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:01:54.018-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 9 + Win 7/R2/Vista/2K8 + vulnerable file versions">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="Vista/2K8/Win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16496" test_ref="oval:org.mitre.oval:tst:81875"/>
            <criteria operator="AND" comment="Check for LDR range">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20606" test_ref="oval:org.mitre.oval:tst:81808"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + Win 7/R2/Win8/2k12 + vulnerable file versions">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16635" test_ref="oval:org.mitre.oval:tst:81840"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.20000" test_ref="oval:org.mitre.oval:tst:80523"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.20742" test_ref="oval:org.mitre.oval:tst:81835"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:17205" version="5" class="vulnerability">
      <metadata>
        <title>Memory corruption vulnerability in Internet Explorer - CVE-2013-3162 (MS13-055)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2013-3162" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3162"/>
        <description>Microsoft Internet Explorer 7 through 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3115.</description>
        <oval_repository>
          <dates>
            <submitted date="2013-07-12T12:43:10">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-07-12T16:13:24.538-04:00">DRAFT</status_change>
            <status_change date="2013-07-29T04:01:21.325-04:00">INTERIM</status_change>
            <status_change date="2013-08-19T04:03:09.248-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:17205 - extended definitions of OS are without SP checks" date="2014-07-28T17:59:00.295-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T18:01:18.967-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:01:53.554-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 7 + Win XP/2K3/Vista/2K8 + vulnerable file versions">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="Check for vulnerable OS and respective file versions">
            <criteria operator="AND" comment="XP/2K3 and vulnerable file versions">
              <criteria operator="OR" comment="XP / 2K3">
                <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
                <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21342" test_ref="oval:org.mitre.oval:tst:81752"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2K8 and vulnerable file versions">
              <criteria operator="OR" comment="Vista / 2K8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.18861" test_ref="oval:org.mitre.oval:tst:81698"/>
                <criteria operator="AND" comment="Check for LDR range">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23133" test_ref="oval:org.mitre.oval:tst:81717"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + Win XP/2K3/Vista/2K8/Win7/R2 + vulnerable file versions">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="Check for vulnerable OS and respective file versions">
            <criteria operator="AND" comment="XP/2K3 and vulnerable file versions">
              <criteria operator="OR" comment="XP / 2K3">
                <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
                <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23507" test_ref="oval:org.mitre.oval:tst:81827"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2K8 and vulnerable file versions">
              <criteria operator="OR" comment="Vista / 2K8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19443" test_ref="oval:org.mitre.oval:tst:81789"/>
                <criteria operator="AND" comment="Check for LDR range">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23507" test_ref="oval:org.mitre.oval:tst:81827"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18170" test_ref="oval:org.mitre.oval:tst:81431"/>
                <criteria operator="AND" comment="Check for LDR range">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22341" test_ref="oval:org.mitre.oval:tst:81329"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + Win 7/R2/Vista/2K8 + vulnerable file versions">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="Vista/2K8/Win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16496" test_ref="oval:org.mitre.oval:tst:81875"/>
            <criteria operator="AND" comment="Check for LDR range">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20606" test_ref="oval:org.mitre.oval:tst:81808"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + Win 7/R2/Win8/2k12 + vulnerable file versions">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16635" test_ref="oval:org.mitre.oval:tst:81840"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.20000" test_ref="oval:org.mitre.oval:tst:80523"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.20742" test_ref="oval:org.mitre.oval:tst:81835"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:17190" version="5" class="vulnerability">
      <metadata>
        <title>Memory corruption vulnerability in Internet Explorer - CVE-2013-3115 (MS13-055)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2013-3115" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3115"/>
        <description>Microsoft Internet Explorer 7 through 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3162.</description>
        <oval_repository>
          <dates>
            <submitted date="2013-07-12T12:43:10">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-07-12T16:13:16.828-04:00">DRAFT</status_change>
            <status_change date="2013-07-29T04:01:20.268-04:00">INTERIM</status_change>
            <status_change date="2013-08-19T04:03:05.905-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:17190 - extended definitions of OS are without SP checks" date="2014-07-28T17:59:00.295-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T18:01:17.899-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:01:53.253-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 7 + Win XP/2K3/Vista/2K8 + vulnerable file versions">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="Check for vulnerable OS and respective file versions">
            <criteria operator="AND" comment="XP/2K3 and vulnerable file versions">
              <criteria operator="OR" comment="XP / 2K3">
                <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
                <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21342" test_ref="oval:org.mitre.oval:tst:81752"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2K8 and vulnerable file versions">
              <criteria operator="OR" comment="Vista / 2K8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.18861" test_ref="oval:org.mitre.oval:tst:81698"/>
                <criteria operator="AND" comment="Check for LDR range">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23133" test_ref="oval:org.mitre.oval:tst:81717"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + Win XP/2K3/Vista/2K8/Win7/R2 + vulnerable file versions">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="Check for vulnerable OS and respective file versions">
            <criteria operator="AND" comment="XP/2K3 and vulnerable file versions">
              <criteria operator="OR" comment="XP / 2K3">
                <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
                <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23507" test_ref="oval:org.mitre.oval:tst:81827"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2K8 and vulnerable file versions">
              <criteria operator="OR" comment="Vista / 2K8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19443" test_ref="oval:org.mitre.oval:tst:81789"/>
                <criteria operator="AND" comment="Check for LDR range">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23507" test_ref="oval:org.mitre.oval:tst:81827"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18170" test_ref="oval:org.mitre.oval:tst:81431"/>
                <criteria operator="AND" comment="Check for LDR range">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22341" test_ref="oval:org.mitre.oval:tst:81329"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + Win 7/R2/Vista/2K8 + vulnerable file versions">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="Vista/2K8/Win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16496" test_ref="oval:org.mitre.oval:tst:81875"/>
            <criteria operator="AND" comment="Check for LDR range">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20606" test_ref="oval:org.mitre.oval:tst:81808"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + Win 7/R2/Win8/2k12 + vulnerable file versions">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16635" test_ref="oval:org.mitre.oval:tst:81840"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.20000" test_ref="oval:org.mitre.oval:tst:80523"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.20742" test_ref="oval:org.mitre.oval:tst:81835"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:17148" version="4" class="vulnerability">
      <metadata>
        <title>Win32k Buffer Overwrite Vulnerability - CVE-2013-3173 (MS13-053)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows 7</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2013-3173" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3173"/>
        <description>Buffer overflow in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT allows local users to gain privileges via a crafted application that leverages improper handling of objects in memory, aka "Win32k Buffer Overwrite Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2013-07-15T19:34:20">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-07-17T16:02:04.471-04:00">DRAFT</status_change>
            <status_change date="2013-08-05T04:00:36.829-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:17148 - Thank you for highlighting it. Issue has been fixed in the attached file." date="2013-08-07T15:51:00.911-04:00">
              <contributor organization="SecPod Technologies">Pooja Shetty</contributor>
            </modified>
            <status_change date="2013-08-26T04:00:17.787-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="XP x86">
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <criterion comment="Check if the version of Win32k.sys is less than 5.1.2600.6404" test_ref="oval:org.mitre.oval:tst:81903"/>
        </criteria>
        <criteria operator="AND" comment="XP/2K3 and vulnerable file version">
          <criteria operator="OR" comment="XP/2K3">
            <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
          </criteria>
          <criterion comment="Check if the version of Win32k.sys is less than 5.2.3790.5174" test_ref="oval:org.mitre.oval:tst:81786"/>
        </criteria>
        <criteria operator="AND" comment="Vista/2K8 and vulnerable file version">
          <criteria operator="OR" comment="Vista/2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
            <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of Win32k.sys is less than 6.0.6002.18861" test_ref="oval:org.mitre.oval:tst:81696"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is less than 6.0.6002.23132" test_ref="oval:org.mitre.oval:tst:81776"/>
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:81723"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="7/2K8 R2 and vulnerable file version">
          <criteria operator="OR" comment="7/2K8 R2">
            <extend_definition comment="Microsoft Windows 7 x64 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12627"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12292"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12583"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12567"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of Win32k.sys is less than 6.1.7601.18176" test_ref="oval:org.mitre.oval:tst:81882"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is less than 6.1.7601.22348" test_ref="oval:org.mitre.oval:tst:81601"/>
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:81763"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="8/2k12 and vulnerable file version">
          <criteria operator="OR" comment="8/2k12">
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of Win32k.sys is less than 6.2.9200.16627" test_ref="oval:org.mitre.oval:tst:81241"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Win32k.sys is less than 6.2.9200.20732" test_ref="oval:org.mitre.oval:tst:81822"/>
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.2.9200.20000" test_ref="oval:org.mitre.oval:tst:80697"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:17088" version="5" class="vulnerability">
      <metadata>
        <title>Memory corruption vulnerability in Internet Explorer - CVE-2013-3151 (MS13-055)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2013-3151" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3151"/>
        <description>Microsoft Internet Explorer 8 through 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3144 and CVE-2013-3163.</description>
        <oval_repository>
          <dates>
            <submitted date="2013-07-12T12:43:10">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-07-12T16:13:22.224-04:00">DRAFT</status_change>
            <status_change date="2013-07-29T04:01:12.797-04:00">INTERIM</status_change>
            <status_change date="2013-08-19T04:02:26.632-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:17088 - extended definitions of OS are without SP checks" date="2014-07-28T17:59:00.295-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T18:01:17.608-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:01:52.978-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 8 + Win XP/2K3/Vista/2K8/Win7/R2 + vulnerable file versions">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="Check for vulnerable OS and respective file versions">
            <criteria operator="AND" comment="XP/2K3 and vulnerable file versions">
              <criteria operator="OR" comment="XP / 2K3">
                <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
                <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23507" test_ref="oval:org.mitre.oval:tst:81827"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2K8 and vulnerable file versions">
              <criteria operator="OR" comment="Vista / 2K8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19443" test_ref="oval:org.mitre.oval:tst:81789"/>
                <criteria operator="AND" comment="Check for LDR range">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23507" test_ref="oval:org.mitre.oval:tst:81827"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18170" test_ref="oval:org.mitre.oval:tst:81431"/>
                <criteria operator="AND" comment="Check for LDR range">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22341" test_ref="oval:org.mitre.oval:tst:81329"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + Win 7/R2/Vista/2K8 + vulnerable file versions">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="Vista/2K8/Win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16496" test_ref="oval:org.mitre.oval:tst:81875"/>
            <criteria operator="AND" comment="Check for LDR range">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20606" test_ref="oval:org.mitre.oval:tst:81808"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + Win 7/R2/Win8/2k12 + vulnerable file versions">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16635" test_ref="oval:org.mitre.oval:tst:81840"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.20000" test_ref="oval:org.mitre.oval:tst:80523"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.20742" test_ref="oval:org.mitre.oval:tst:81835"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:17071" version="8" class="vulnerability">
      <metadata>
        <title>Array allocation vulnerability in the Common Language Runtime (CLR) in Microsoft .NET Framework - MS13-052</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft .NET Framework 2.0</product>
          <product>Microsoft .NET Framework 3.5</product>
          <product>Microsoft .NET Framework 3.5.1</product>
          <product>Microsoft .NET Framework 4.0</product>
          <product>Microsoft .NET Framework 4.5</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2013-3134" ref_url="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2013-3134"/>
        <description>The Common Language Runtime (CLR) in Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, and 4.5 on 64-bit platforms does not properly allocate arrays of structures, which allows remote attackers to execute arbitrary code via a crafted .NET Framework application that changes array data, aka "Array Allocation Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2013-07-15T10:59:59">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-07-17T16:01:45.279-04:00">DRAFT</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:81826 - obj:15823 replaced obj:2009 because .net 4 is testing" date="2013-07-19T08:44:00.954-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-08-05T04:00:30.791-04:00">INTERIM</status_change>
            <status_change date="2013-08-26T04:00:16.012-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:17071 - .NET Framework 3.5.1 instead .NET Framework 3.5 in Windows 8 and Windows Server 2012" date="2014-03-31T14:51:00.481-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-03-31T14:53:51.773-04:00">INTERIM</status_change>
            <status_change date="2014-04-21T04:00:16.276-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:17071 - extended definitions of OS are without SP checks" date="2014-07-28T17:59:00.295-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T18:01:23.358-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:01:52.656-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment=".net 2.0 sp2/xp/server 2003/versions">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 2.0 Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6158"/>
          <criteria operator="OR" comment="either file versions GDR/LDR">
            <criterion comment="Check if the version of mscorlib.dll is less than 2.0.50727.3649" test_ref="oval:org.mitre.oval:tst:81523"/>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of mscorlib.dll is less than 2.0.50727.7026" test_ref="oval:org.mitre.oval:tst:81025"/>
              <criterion comment="Check if the version of mscorlib.dll is greater than or equal to 2.0.50727.7000" test_ref="oval:org.mitre.oval:tst:80994"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment=".net 2.0 sp2/vista/server 2008/versions">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 2.0 Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6158"/>
          <criteria operator="OR" comment="either file versions">
            <criterion comment="Check if the version of mscorlib.dll is less than 2.0.50727.4241" test_ref="oval:org.mitre.oval:tst:80941"/>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of mscorlib.dll is less than 2.0.50727.7025" test_ref="oval:org.mitre.oval:tst:81880"/>
              <criterion comment="Check if the version of mscorlib.dll is greater than or equal to 2.0.50727.7000" test_ref="oval:org.mitre.oval:tst:80994"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment=".net 3.5/win8/server 2012/versions">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 3.5 SP1 is installed" definition_ref="oval:org.mitre.oval:def:12542"/>
          <criteria operator="OR" comment="either file versions">
            <criterion comment="Check if the version of mscorlib.dll is less than 2.0.50727.6407" test_ref="oval:org.mitre.oval:tst:81653"/>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of mscorlib.dll is less than 2.0.50727.7025" test_ref="oval:org.mitre.oval:tst:81880"/>
              <criterion comment="Check if the version of mscorlib.dll is greater than or equal to 2.0.50727.7000" test_ref="oval:org.mitre.oval:tst:80994"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment=".net 3.5.1/win 7/server 2008 R2/versions">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 3.5 SP1 is installed" definition_ref="oval:org.mitre.oval:def:12542"/>
          <criteria operator="OR" comment="either file versions">
            <criterion comment="Check if the version of mscorlib.dll is less than 2.0.50727.5472" test_ref="oval:org.mitre.oval:tst:81766"/>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of mscorlib.dll is less than 2.0.50727.7025" test_ref="oval:org.mitre.oval:tst:81880"/>
              <criterion comment="Check if the version of mscorlib.dll is greater than or equal to 2.0.50727.7000" test_ref="oval:org.mitre.oval:tst:80994"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment=".net 4.0/win xp.server 2003/vista/server 2008/win 7/server 2008 R2/versions">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6749"/>
          <criteria operator="OR" comment="either file versions">
            <criterion comment="Check if the version of mscorlib.dll is less than 4.0.30319.1008" test_ref="oval:org.mitre.oval:tst:81442"/>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of mscorlib.dll is less than 4.0.30319.2012" test_ref="oval:org.mitre.oval:tst:81826"/>
              <criterion comment="Check if the version of mscorlib.dll is greater than or equal to 4.0.30319.2000" test_ref="oval:org.mitre.oval:tst:81701"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment=".net 4.5/vista/server 2008/win 7/server 2008 R2/versions">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 4.5 is installed" definition_ref="oval:org.mitre.oval:def:15925"/>
          <criteria operator="OR" comment="either file versions">
            <criterion comment="Check if the version of mscorlib.dll is less than 4.0.30319.18052" test_ref="oval:org.mitre.oval:tst:81273"/>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of mscorlib.dll is less than 4.0.30319.19080" test_ref="oval:org.mitre.oval:tst:81487"/>
              <criterion comment="Check if the version of mscorlib.dll is greater than or equal to 4.0.30319.19000" test_ref="oval:org.mitre.oval:tst:80125"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment=".net 4.5/win 8/server 2012/versions">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 4.5 is installed" definition_ref="oval:org.mitre.oval:def:15925"/>
          <criteria operator="OR" comment="either file versions">
            <criterion comment="Check if the version of mscorlib.dll is less than 4.0.30319.18051" test_ref="oval:org.mitre.oval:tst:81655"/>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of mscorlib.dll is less than 4.0.30319.19079" test_ref="oval:org.mitre.oval:tst:81054"/>
              <criterion comment="Check if the version of mscorlib.dll is greater than or equal to 4.0.30319.19000" test_ref="oval:org.mitre.oval:tst:80125"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:17034" version="5" class="vulnerability">
      <metadata>
        <title>Memory corruption vulnerability in Internet Explorer - CVE-2013-3148 (MS13-055)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2013-3148" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3148"/>
        <description>Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3153.</description>
        <oval_repository>
          <dates>
            <submitted date="2013-07-12T12:43:10">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-07-12T16:13:20.583-04:00">DRAFT</status_change>
            <status_change date="2013-07-29T04:01:09.063-04:00">INTERIM</status_change>
            <status_change date="2013-08-19T04:02:14.432-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:17034 - extended definitions of OS are without SP checks" date="2014-07-28T17:59:00.295-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T18:01:22.591-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:01:52.268-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + Win XP/2K3 + vulnerable file versions">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="Check for vulnerable OS and respective file versions">
            <criteria operator="AND" comment="XP X86 and vulnerable file version">
              <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
              <criterion comment="Check if the version of mshtml.dll is less than 6.0.2900.6400" test_ref="oval:org.mitre.oval:tst:81844"/>
            </criteria>
            <criteria operator="AND" comment="XP X64 / 2K3 and vulnerable file version">
              <criteria operator="OR" comment="XP X64 / 2K3">
                <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5170" test_ref="oval:org.mitre.oval:tst:81724"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 7 + Win XP/2K3/Vista/2K8 + vulnerable file versions">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="Check for vulnerable OS and respective file versions">
            <criteria operator="AND" comment="XP/2K3 and vulnerable file versions">
              <criteria operator="OR" comment="XP / 2K3">
                <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
                <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21342" test_ref="oval:org.mitre.oval:tst:81752"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2K8 and vulnerable file versions">
              <criteria operator="OR" comment="Vista / 2K8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.18861" test_ref="oval:org.mitre.oval:tst:81698"/>
                <criteria operator="AND" comment="Check for LDR range">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23133" test_ref="oval:org.mitre.oval:tst:81717"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + Win XP/2K3/Vista/2K8/Win7/R2 + vulnerable file versions">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="Check for vulnerable OS and respective file versions">
            <criteria operator="AND" comment="XP/2K3 and vulnerable file versions">
              <criteria operator="OR" comment="XP / 2K3">
                <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
                <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23507" test_ref="oval:org.mitre.oval:tst:81827"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2K8 and vulnerable file versions">
              <criteria operator="OR" comment="Vista / 2K8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19443" test_ref="oval:org.mitre.oval:tst:81789"/>
                <criteria operator="AND" comment="Check for LDR range">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23507" test_ref="oval:org.mitre.oval:tst:81827"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18170" test_ref="oval:org.mitre.oval:tst:81431"/>
                <criteria operator="AND" comment="Check for LDR range">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22341" test_ref="oval:org.mitre.oval:tst:81329"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + Win 7/R2/Vista/2K8 + vulnerable file versions">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="Vista/2K8/Win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16496" test_ref="oval:org.mitre.oval:tst:81875"/>
            <criteria operator="AND" comment="Check for LDR range">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20606" test_ref="oval:org.mitre.oval:tst:81808"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + Win 7/R2/Win8/2k12 + vulnerable file versions">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16635" test_ref="oval:org.mitre.oval:tst:81840"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.20000" test_ref="oval:org.mitre.oval:tst:80523"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.20742" test_ref="oval:org.mitre.oval:tst:81835"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:17024" version="5" class="vulnerability">
      <metadata>
        <title>Memory corruption vulnerability in Internet Explorer - CVE-2013-3144 (MS13-055)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2013-3144" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3144"/>
        <description>Microsoft Internet Explorer 8 through 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3151 and CVE-2013-3163.</description>
        <oval_repository>
          <dates>
            <submitted date="2013-07-12T12:43:10">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-07-12T16:13:18.101-04:00">DRAFT</status_change>
            <status_change date="2013-07-29T04:01:07.700-04:00">INTERIM</status_change>
            <status_change date="2013-08-19T04:02:12.484-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:17024 - extended definitions of OS are without SP checks" date="2014-07-28T17:59:00.295-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T18:01:21.810-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:01:52.016-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 8 + Win XP/2K3/Vista/2K8/Win7/R2 + vulnerable file versions">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="Check for vulnerable OS and respective file versions">
            <criteria operator="AND" comment="XP/2K3 and vulnerable file versions">
              <criteria operator="OR" comment="XP / 2K3">
                <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
                <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23507" test_ref="oval:org.mitre.oval:tst:81827"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2K8 and vulnerable file versions">
              <criteria operator="OR" comment="Vista / 2K8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19443" test_ref="oval:org.mitre.oval:tst:81789"/>
                <criteria operator="AND" comment="Check for LDR range">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23507" test_ref="oval:org.mitre.oval:tst:81827"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18170" test_ref="oval:org.mitre.oval:tst:81431"/>
                <criteria operator="AND" comment="Check for LDR range">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22341" test_ref="oval:org.mitre.oval:tst:81329"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + Win 7/R2/Vista/2K8 + vulnerable file versions">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="Vista/2K8/Win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16496" test_ref="oval:org.mitre.oval:tst:81875"/>
            <criteria operator="AND" comment="Check for LDR range">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20606" test_ref="oval:org.mitre.oval:tst:81808"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + Win 7/R2/Win8/2k12 + vulnerable file versions">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16635" test_ref="oval:org.mitre.oval:tst:81840"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.20000" test_ref="oval:org.mitre.oval:tst:80523"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.20742" test_ref="oval:org.mitre.oval:tst:81835"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:16975" version="5" class="vulnerability">
      <metadata>
        <title>Memory corruption vulnerability in Internet Explorer - CVE-2013-3152 (MS13-055)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <product>Microsoft Internet Explorer 10</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2013-3152" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3152"/>
        <description>Microsoft Internet Explorer 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3146.</description>
        <oval_repository>
          <dates>
            <submitted date="2013-07-12T12:43:10">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-07-12T16:13:22.831-04:00">DRAFT</status_change>
            <status_change date="2013-07-29T04:01:03.841-04:00">INTERIM</status_change>
            <status_change date="2013-08-19T04:02:03.794-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:16975 - extended definitions of OS are without SP checks" date="2014-07-28T17:59:00.295-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T18:01:17.405-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:01:51.146-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
        <criteria operator="OR" comment="Win 7 / R2">
          <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
          <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
          <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
          <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
          <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
        </criteria>
        <criteria operator="OR" comment="Check for vulnerable version">
          <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16635" test_ref="oval:org.mitre.oval:tst:81840"/>
          <criteria operator="AND" comment="Check for LDR">
            <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.20000" test_ref="oval:org.mitre.oval:tst:80523"/>
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.20742" test_ref="oval:org.mitre.oval:tst:81835"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:16943" version="3" class="vulnerability">
      <metadata>
        <title>Vulnerability in Kernel-Mode Driver Could Allow Denial of Service - MS13-049</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Vista</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2013-3138" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3138"/>
        <description>Integer overflow in the TCP/IP kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT allows remote attackers to cause a denial of service (system hang) via crafted TCP packets, aka "TCP/IP Integer Overflow Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2013-06-13T20:21:09">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-06-13T14:08:53.298-04:00">DRAFT</status_change>
            <status_change date="2013-07-01T04:01:41.308-04:00">INTERIM</status_change>
            <status_change date="2013-07-22T04:01:56.969-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vista/2K8 and vulnerable file version">
          <criteria operator="OR" comment="Vista/2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
            <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of tcpip.sys is less than 6.0.6002.18835" test_ref="oval:org.mitre.oval:tst:81147"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of tcpip.sys is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80825"/>
              <criterion comment="Check if the version of tcpip.sys is less than 6.0.6002.23106" test_ref="oval:org.mitre.oval:tst:80326"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / 2k8 R2 SP1">
          <criteria operator="OR" comment="Win 7 / 2K8 R2 SP1">
            <extend_definition comment="Microsoft Windows 7 (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12292"/>
            <extend_definition comment="Microsoft Windows 7 x64 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12627"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12567"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12583"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of tcpip.sys is less than 6.1.7601.18148" test_ref="oval:org.mitre.oval:tst:81178"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of tcpip.sys is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:81171"/>
              <criterion comment="Check if the version of tcpip.sys is less than 6.1.7601.22319" test_ref="oval:org.mitre.oval:tst:80827"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8 / 2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2K12">
            <extend_definition comment="Microsoft Windows 8 is installed" definition_ref="oval:org.mitre.oval:def:15732"/>
            <extend_definition comment="Microsoft Windows Server 2012 is installed" definition_ref="oval:org.mitre.oval:def:16359"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of tcpip.sys is less than 6.2.9200.16604" test_ref="oval:org.mitre.oval:tst:81318"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of tcpip.sys is less than 6.2.9200.20708" test_ref="oval:org.mitre.oval:tst:81201"/>
              <criterion comment="Check if the version of tcpip.sys is greater than or equal to 6.2.9200.20000" test_ref="oval:org.mitre.oval:tst:80315"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:16927" version="5" class="vulnerability">
      <metadata>
        <title>Memory corruption vulnerability in Internet Explorer - CVE-2013-3153 (MS13-055)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2013-3153" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3153"/>
        <description>Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3148.</description>
        <oval_repository>
          <dates>
            <submitted date="2013-07-12T12:43:10">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-07-12T16:13:23.182-04:00">DRAFT</status_change>
            <status_change date="2013-07-29T04:00:59.520-04:00">INTERIM</status_change>
            <status_change date="2013-08-19T04:01:57.392-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:16927 - extended definitions of OS are without SP checks" date="2014-07-28T17:59:00.295-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T18:01:23.835-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:01:50.589-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + Win XP/2K3 + vulnerable file versions">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="Check for vulnerable OS and respective file versions">
            <criteria operator="AND" comment="XP X86 and vulnerable file version">
              <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
              <criterion comment="Check if the version of mshtml.dll is less than 6.0.2900.6400" test_ref="oval:org.mitre.oval:tst:81844"/>
            </criteria>
            <criteria operator="AND" comment="XP X64 / 2K3 and vulnerable file version">
              <criteria operator="OR" comment="XP X64 / 2K3">
                <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5170" test_ref="oval:org.mitre.oval:tst:81724"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 7 + Win XP/2K3/Vista/2K8 + vulnerable file versions">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="Check for vulnerable OS and respective file versions">
            <criteria operator="AND" comment="XP/2K3 and vulnerable file versions">
              <criteria operator="OR" comment="XP / 2K3">
                <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
                <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21342" test_ref="oval:org.mitre.oval:tst:81752"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2K8 and vulnerable file versions">
              <criteria operator="OR" comment="Vista / 2K8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.18861" test_ref="oval:org.mitre.oval:tst:81698"/>
                <criteria operator="AND" comment="Check for LDR range">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23133" test_ref="oval:org.mitre.oval:tst:81717"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + Win XP/2K3/Vista/2K8/Win7/R2 + vulnerable file versions">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="Check for vulnerable OS and respective file versions">
            <criteria operator="AND" comment="XP/2K3 and vulnerable file versions">
              <criteria operator="OR" comment="XP / 2K3">
                <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
                <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23507" test_ref="oval:org.mitre.oval:tst:81827"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2K8 and vulnerable file versions">
              <criteria operator="OR" comment="Vista / 2K8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19443" test_ref="oval:org.mitre.oval:tst:81789"/>
                <criteria operator="AND" comment="Check for LDR range">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23507" test_ref="oval:org.mitre.oval:tst:81827"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18170" test_ref="oval:org.mitre.oval:tst:81431"/>
                <criteria operator="AND" comment="Check for LDR range">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22341" test_ref="oval:org.mitre.oval:tst:81329"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + Win 7/R2/Vista/2K8 + vulnerable file versions">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="Vista/2K8/Win7/R2">
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16496" test_ref="oval:org.mitre.oval:tst:81875"/>
            <criteria operator="AND" comment="Check for LDR range">
              <criterion comment="Check for mshtml.dll version greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:79777"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20606" test_ref="oval:org.mitre.oval:tst:81808"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + Win 7/R2/Win8/2k12 + vulnerable file versions">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16635" test_ref="oval:org.mitre.oval:tst:81840"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.20000" test_ref="oval:org.mitre.oval:tst:80523"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.20742" test_ref="oval:org.mitre.oval:tst:81835"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:16925" version="4" class="vulnerability">
      <metadata>
        <title>Vulnerability in the Management Pack for Oracle GoldenGate Server. Supported versions that are affected are 11.1.1.1.0.
		Vulnerability in the Oracle GoldenGate Veridata component of Oracle Fusion Middleware (subcomponent: Server). The supported version that is affected is 3.0.0.11.0. Easily exploitable vulnerability allows successful unauthenticated network attacks via HTTP. Successful attack of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle GoldenGate Veridata</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <product>Oracle GoldenGate Director</product>
          <product>Oracle GoldenGate Veridata</product>
        </affected>
        <reference ref_id="CVE-2012-0022" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0022" source="CVE"/>
        <description>Apache Tomcat 5.5.x before 5.5.35, 6.x before 6.0.34, and 7.x before 7.0.23 uses an inefficient approach for handling parameters, which allows remote attackers to cause a denial of service (CPU consumption) via a request that contains many parameters and parameter values, a different vulnerability than CVE-2011-4858.</description>
        <oval_repository>
          <dates>
            <submitted date="2013-04-29T10:26:26.748+04:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2013-06-19T16:06:43.613-04:00">DRAFT</status_change>
            <status_change date="2013-07-08T04:02:15.887-04:00">INTERIM</status_change>
            <status_change date="2013-07-29T04:00:59.180-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criterion comment="Check if version of Oracle GoldenGate Director is 11.1.1.1.0" test_ref="oval:org.mitre.oval:tst:81231"/>
        <criterion comment="Check if version for Oracle GoldenGate Veridata is 3.0.0.11.0" test_ref="oval:org.mitre.oval:tst:80940"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:16917" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability (CVE-2013-3118) - MS13-047</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <product>Microsoft Internet Explorer 10</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2013-3118" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3118"/>
        <description>Microsoft Internet Explorer 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3120 and CVE-2013-3125.</description>
        <oval_repository>
          <dates>
            <submitted date="2013-06-13T13:15:31">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-06-13T14:21:12.054-04:00">DRAFT</status_change>
            <status_change date="2013-07-01T04:01:37.218-04:00">INTERIM</status_change>
            <status_change date="2013-07-22T04:01:50.770-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:16917 - extended definitions of OS are without SP checks" date="2014-07-28T17:57:00.076-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T17:59:09.243-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:01:50.389-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
        <criteria operator="OR" comment="Check for vulnerable OS and respective file versions">
          <criteria operator="AND" comment="Win 7 / R2 and vulnerable file version">
            <criteria operator="OR" comment="Win 7 / R2">
              <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
              <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
              <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            </criteria>
            <criteria operator="OR" comment="Check for vulnerable version">
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16614" test_ref="oval:org.mitre.oval:tst:81263"/>
              <criteria operator="AND" comment="Check for LDR">
                <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.20000" test_ref="oval:org.mitre.oval:tst:80523"/>
                <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.20719" test_ref="oval:org.mitre.oval:tst:81274"/>
              </criteria>
            </criteria>
          </criteria>
          <criteria operator="AND" comment="Win 8 / 2K12 and vulnerable file version">
            <criteria operator="OR" comment="Win 8 / 2K12">
              <extend_definition comment="Microsoft Windows 8 is installed" definition_ref="oval:org.mitre.oval:def:15732"/>
              <extend_definition comment="Microsoft Windows Server 2012 is installed" definition_ref="oval:org.mitre.oval:def:16359"/>
            </criteria>
            <criteria operator="OR" comment="Check for vulnerable version">
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16612" test_ref="oval:org.mitre.oval:tst:81283"/>
              <criteria operator="AND" comment="Check for LDR ranges">
                <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.20000" test_ref="oval:org.mitre.oval:tst:80523"/>
                <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.20717" test_ref="oval:org.mitre.oval:tst:81236"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:16883" version="3" class="vulnerability">
      <metadata>
        <title>DirectShow Arbitrary Memory Overwrite Vulnerability - MS13-056</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2013-3174" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3174"/>
        <description>DirectShow in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, and Windows Server 2012 allows remote attackers to execute arbitrary code via a crafted GIF file, aka "DirectShow Arbitrary Memory Overwrite Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2012-07-11T12:04:24">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-07-12T16:32:12.221-04:00">DRAFT</status_change>
            <status_change date="2013-07-29T04:00:56.124-04:00">INTERIM</status_change>
            <status_change date="2013-08-19T04:01:53.261-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Win XP and vulnerable file version">
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <criterion comment="Check if the version of qedit.dll is less than 6.5.2600.6404" test_ref="oval:org.mitre.oval:tst:81512"/>
        </criteria>
        <criteria operator="AND" comment="XP x64 / 2k3(all) and vulnerable file version">
          <criteria operator="OR" comment="XP X64 / 2K3">
            <extend_definition comment="Microsoft Windows XP SP2 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:1799"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
          </criteria>
          <criterion comment="Check if the version of qedit.dll is less than 6.5.3790.5174" test_ref="oval:org.mitre.oval:tst:81737"/>
        </criteria>
        <criteria operator="AND" comment="Vista/2K8 and vulnerable file version">
          <criteria operator="OR" comment="Vista / 2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
            <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of qedit.dll is less than 6.6.6002.18860" test_ref="oval:org.mitre.oval:tst:81867"/>
            <criteria operator="AND" comment="Check for LDR range">
              <criterion comment="Check if the version of qedit.dll is greater than or equal to 6.6.6002.23000" test_ref="oval:org.mitre.oval:tst:81807"/>
              <criterion comment="Check if the version of qedit.dll is less than 6.6.6002.23132" test_ref="oval:org.mitre.oval:tst:81076"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / R2 and vulnerable version">
          <criteria operator="OR" comment="Win 7 / R2">
            <extend_definition comment="Microsoft Windows 7 (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12292"/>
            <extend_definition comment="Microsoft Windows 7 x64 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12627"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12567"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12583"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of qedit.dll is less than 6.6.7601.18175" test_ref="oval:org.mitre.oval:tst:81855"/>
            <criteria operator="AND" comment="Check for LDR range">
              <criterion comment="Check if the version of qedit.dll is greater than or equal to 6.6.7601.22000" test_ref="oval:org.mitre.oval:tst:81771"/>
              <criterion comment="Check if the version of qedit.dll is less than 6.6.7601.22348" test_ref="oval:org.mitre.oval:tst:81342"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8 / 2k12 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 / 2k12">
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of qedit.dll is less than 6.6.9200.16628" test_ref="oval:org.mitre.oval:tst:81836"/>
            <criteria operator="AND" comment="Check for LDR range">
              <criterion comment="Check if the version of qedit.dll is greater than or equal to 6.6.9200.20000" test_ref="oval:org.mitre.oval:tst:81492"/>
              <criterion comment="Check if the version of qedit.dll is less than 6.6.9200.20733" test_ref="oval:org.mitre.oval:tst:81285"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1799" version="7" class="inventory">
      <metadata>
        <title>Microsoft Windows XP SP2 (64-bit) is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/o:microsoft:windows_xp::sp2:64bit"/>
        <description>The operating system installed on the system is Microsoft Windows XP SP2 (64-bit).</description>
        <oval_repository>
          <dates>
            <submitted date="2007-04-11T08:08:51">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2007-04-12T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2007-04-30T08:18:47.475-04:00">INTERIM</status_change>
            <status_change date="2007-05-23T15:05:31.948-04:00">ACCEPTED</status_change>
            <modified comment="Changed the CPE reference" date="2008-04-04T11:17:00.158-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2008-04-04T11:24:05.185-04:00">INTERIM</status_change>
            <status_change date="2008-04-21T04:00:14.000-04:00">ACCEPTED</status_change>
            <modified comment="Multiple corrections and update to POSIX compatibility for ste:2656" date="2010-11-29T16:12:00.873-05:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2010-11-29T16:13:01.116-05:00">INTERIM</status_change>
            <status_change date="2010-12-20T04:00:35.777-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Added an additional test for Windows Server 2003 platforms to test for the existence of the NT Directory Services" date="2011-04-25T14:34:00.432-04:00">
              <contributor organization="Telos">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2011-04-25T14:46:31.988-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:717 - Reverted mistaken switch of obj:717 (Service Pack) and obj:15869 (NT Directory Services)" date="2011-04-26T11:53:00.464-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-16T04:01:52.116-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Microsoft Windows XP is installed" definition_ref="oval:org.mitre.oval:def:105"/>
        <criterion comment="a version of Windows for the ia64 architecture is installed" test_ref="oval:org.mitre.oval:tst:2747"/>
        <criterion comment="Win2K/XP/2003 service pack 2 (or later) is installed" test_ref="oval:org.mitre.oval:tst:2837"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:105" version="5" class="inventory">
      <metadata>
        <title>Microsoft Windows XP is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/o:microsoft:windows_xp"/>
        <description>The operating system installed on the system is Microsoft Windows XP.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-06-26T12:55:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <status_change date="2006-06-26T12:55:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Added CPE reference." date="2007-04-30T07:48:00.244-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-04-30T08:01:55.267-04:00">INTERIM</status_change>
            <status_change date="2007-05-23T15:05:25.969-04:00">ACCEPTED</status_change>
            <modified comment="Changed the CPE reference" date="2008-04-04T11:17:00.073-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2008-04-04T11:27:52.098-04:00">INTERIM</status_change>
            <status_change date="2008-04-21T04:00:10.499-04:00">ACCEPTED</status_change>
            <modified comment="Changed the test for windows to be case insensitive and replaced the test for Windows 5.1 with a new test for Windows XP" date="2009-12-02T16:05:00.749-04:00">
              <contributor organization="National Institute of Standards and Technology">Tim Harrison</contributor>
            </modified>
            <status_change date="2009-12-02T16:05:00.749-04:00">INTERIM</status_change>
            <modified comment="Added anchors and spaces to regular expression" date="2009-12-04T14:56:00.359-05:00">
              <contributor organization="National Institute of Standards and Technology">Tim Harrison</contributor>
            </modified>
            <modified comment="Updating regex to include parenthesis" date="2009-12-08T17:32:00.792-05:00">
              <contributor organization="National Institute of Standards and Technology">Tim Harrison</contributor>
            </modified>
            <status_change date="2010-01-04T04:01:15.920-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="the installed operating system is part of the Microsoft Windows family" test_ref="oval:org.mitre.oval:tst:99"/>
        <criterion comment="Windows XP is installed" test_ref="oval:org.mitre.oval:tst:11179"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:16875" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability (CVE-2013-3121) - MS13-047</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2013-3121" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3121"/>
        <description>Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3112, CVE-2013-3113, CVE-2013-3139, and CVE-2013-3142.</description>
        <oval_repository>
          <dates>
            <submitted date="2013-06-13T13:15:31">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-06-13T14:21:13.107-04:00">DRAFT</status_change>
            <status_change date="2013-07-01T04:01:29.639-04:00">INTERIM</status_change>
            <status_change date="2013-07-22T04:01:39.199-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:16875 - extended definitions of OS are without SP checks" date="2014-07-28T17:57:00.076-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T17:59:05.677-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:01:49.694-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + Win XP/2K3 + vulnerable file versions">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="Check for vulnerable OS and respective file versions">
            <criteria operator="AND" comment="XP X86 and vulnerable file version">
              <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
              <criterion comment="Check if the version of mshtml.dll is less than 6.0.2900.6391" test_ref="oval:org.mitre.oval:tst:81194"/>
            </criteria>
            <criteria operator="AND" comment="XP X64 / 2K3 and vulnerable file version">
              <criteria operator="OR" comment="XP X64 / 2K3">
                <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5161" test_ref="oval:org.mitre.oval:tst:81056"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 7 + Win XP/2K3/Vista/2K8 + vulnerable file versions">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="Check for vulnerable OS and respective file versions">
            <criteria operator="AND" comment="XP/2K3 and vulnerable file versions">
              <criteria operator="OR" comment="XP / 2K3">
                <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
                <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21337" test_ref="oval:org.mitre.oval:tst:81097"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2K8 and vulnerable file versions">
              <criteria operator="OR" comment="Vista / 2K8">
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.18837" test_ref="oval:org.mitre.oval:tst:81234"/>
                <criteria operator="AND" comment="Check for LDR range">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23109" test_ref="oval:org.mitre.oval:tst:81167"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + Win XP/2K3/Vista/2K8/Win7/R2 + vulnerable file versions">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="Check for vulnerable OS and respective file versions">
            <criteria operator="AND" comment="XP/2K3 and vulnerable file versions">
              <criteria operator="OR" comment="XP / 2K3">
                <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
                <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23501" test_ref="oval:org.mitre.oval:tst:80741"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2K8 and vulnerable file versions">
              <criteria operator="OR" comment="Vista / 2K8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19437" test_ref="oval:org.mitre.oval:tst:81287"/>
                <criteria operator="AND" comment="Check for LDR range">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23501" test_ref="oval:org.mitre.oval:tst:80741"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18156" test_ref="oval:org.mitre.oval:tst:81108"/>
                <criteria operator="AND" comment="Check for LDR range">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22326" test_ref="oval:org.mitre.oval:tst:81049"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + Win 7/R2/Vista/2K8 + vulnerable file versions">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="Vista/2K8/Win7/R2">
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16490" test_ref="oval:org.mitre.oval:tst:81066"/>
            <criteria operator="AND" comment="Check for LDR range">
              <criterion comment="Mshtml.dll version is greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:42899"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20600" test_ref="oval:org.mitre.oval:tst:81015"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + Win 7/R2/Win8/2k12 + vulnerable file versions">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Check for vulnerable OS and respective file versions">
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file version">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16614" test_ref="oval:org.mitre.oval:tst:81263"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.20000" test_ref="oval:org.mitre.oval:tst:80523"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.20719" test_ref="oval:org.mitre.oval:tst:81274"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 8 / 2K12 and vulnerable file version">
              <criteria operator="OR" comment="Win 8 / 2K12">
                <extend_definition comment="Microsoft Windows 8 is installed" definition_ref="oval:org.mitre.oval:def:15732"/>
                <extend_definition comment="Microsoft Windows Server 2012 is installed" definition_ref="oval:org.mitre.oval:def:16359"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16612" test_ref="oval:org.mitre.oval:tst:81283"/>
                <criteria operator="AND" comment="Check for LDR ranges">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.20000" test_ref="oval:org.mitre.oval:tst:80523"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.20717" test_ref="oval:org.mitre.oval:tst:81236"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:16867" version="7" class="vulnerability">
      <metadata>
        <title>Delegate serialization vulnerability in Microsoft .NET Framework - MS13-052</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft .NET Framework 2.0</product>
          <product>Microsoft .NET Framework 3.5</product>
          <product>Microsoft .NET Framework 3.5.1</product>
          <product>Microsoft .NET Framework 4.0</product>
          <product>Microsoft .NET Framework 4.5</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2013-3171" ref_url="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2013-3171"/>
        <description>The serialization functionality in Microsoft .NET Framework 2.0 SP2, 3.5, 3.5 SP1, 3.5.1, 4, and 4.5 does not properly check the permissions of delegate objects, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (XBAP) or (2) a crafted .NET Framework application that leverages a partial-trust relationship, aka "Delegate Serialization Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2013-07-15T10:59:59">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-07-17T16:01:43.222-04:00">DRAFT</status_change>
            <status_change date="2013-08-05T04:00:21.474-04:00">INTERIM</status_change>
            <status_change date="2013-08-26T04:00:12.623-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:16867 - .NET Framework 3.5.1 instead .NET Framework 3.5 in Windows 8 and Windows Server 2012" date="2014-03-31T14:51:00.481-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-03-31T14:53:51.476-04:00">INTERIM</status_change>
            <status_change date="2014-04-21T04:00:15.800-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:16867 - extended definitions of OS are without SP checks" date="2014-07-28T17:59:00.295-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T18:01:18.603-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:01:49.164-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment=".net 2.0 sp2/xp/server 2003/versions">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 2.0 Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6158"/>
          <criteria operator="OR" comment="GDR/LDR">
            <criterion comment="Check if the version of system.configuration.dll is less than 2.0.50727.3650" test_ref="oval:org.mitre.oval:tst:81751"/>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of system.configuration.dll is greater than or equal to 2.0.50727.7000" test_ref="oval:org.mitre.oval:tst:81804"/>
              <criterion comment="Check if the version of system.configuration.dll is less than 2.0.50727.7028" test_ref="oval:org.mitre.oval:tst:81503"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment=".net 2.0 sp2/vista/server 2008/versions">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 2.0 Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6158"/>
          <criteria operator="OR" comment="GDR/LDR">
            <criterion comment="Check if the version of system.configuration.dll is less than 2.0.50727.4243" test_ref="oval:org.mitre.oval:tst:81801"/>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of system.configuration.dll is greater than or equal to 2.0.50727.7000" test_ref="oval:org.mitre.oval:tst:81804"/>
              <criterion comment="Check if the version of system.configuration.dll is less than 2.0.50727.7030" test_ref="oval:org.mitre.oval:tst:81773"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment=".net 3.5/win8/server 2012/versions">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 3.5 SP1 is installed" definition_ref="oval:org.mitre.oval:def:12542"/>
          <criteria operator="OR" comment="either file versions">
            <criterion comment="Check if the version of system.configuration.dll is less than 2.0.50727.6408" test_ref="oval:org.mitre.oval:tst:81465"/>
            <criterion comment="Check if the version of system.data.linq.dll is less than 3.5.30729.6404" test_ref="oval:org.mitre.oval:tst:81756"/>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of system.configuration.dll is less than 2.0.50727.7027" test_ref="oval:org.mitre.oval:tst:81543"/>
              <criterion comment="Check if the version of system.configuration.dll is greater than or equal to 2.0.50727.7000" test_ref="oval:org.mitre.oval:tst:81804"/>
            </criteria>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of system.data.linq.dll is less than 3.5.30729.7048" test_ref="oval:org.mitre.oval:tst:80908"/>
              <criterion comment="Check if the version of system.data.linq.dll is greater than or equal to 3.5.30729.7000" test_ref="oval:org.mitre.oval:tst:81042"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment=".net 3.5 sp1/win xp/server 2003/vista/server 2008/versions">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 3.5 SP1 is installed" definition_ref="oval:org.mitre.oval:def:12542"/>
          <criteria operator="OR" comment="GDR/LDR">
            <criterion comment="Check if the version of system.data.linq.dll is less than 3.5.30729.4052" test_ref="oval:org.mitre.oval:tst:81713"/>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of system.data.linq.dll is less than 3.5.30729.7049" test_ref="oval:org.mitre.oval:tst:81727"/>
              <criterion comment="Check if the version of system.data.linq.dll is greater than or equal to 3.5.30729.7000" test_ref="oval:org.mitre.oval:tst:81042"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment=".net 3.5.1/win 7/server 2008 R2/versions">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 3.5 SP1 is installed" definition_ref="oval:org.mitre.oval:def:12542"/>
          <criteria operator="OR" comment="either file versions">
            <criterion comment="Check if the version of system.configuration.dll is less than 2.0.50727.5473" test_ref="oval:org.mitre.oval:tst:81906"/>
            <criterion comment="Check if the version of system.data.linq.dll is less than 3.5.30729.5455" test_ref="oval:org.mitre.oval:tst:81682"/>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of system.data.linq.dll is greater than or equal to 3.5.30729.7000" test_ref="oval:org.mitre.oval:tst:81042"/>
              <criterion comment="Check if the version of system.data.linq.dll is less than 3.5.30729.7048" test_ref="oval:org.mitre.oval:tst:80908"/>
            </criteria>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of system.configuration.dll is less than 2.0.50727.7027" test_ref="oval:org.mitre.oval:tst:81543"/>
              <criterion comment="Check if the version of system.configuration.dll is greater than or equal to 2.0.50727.7000" test_ref="oval:org.mitre.oval:tst:81804"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment=".net 4.0/win xp.server 2003/vista/server 2008/win 7/server 2008 R2/versions">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6749"/>
          <criteria operator="OR" comment="GDR/LDR">
            <criterion comment="Check if the version of system.data.linq.dll is less than 4.0.30319.1009" test_ref="oval:org.mitre.oval:tst:81344"/>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of system.data.linq.dll is less than 4.0.30319.2013" test_ref="oval:org.mitre.oval:tst:81448"/>
              <criterion comment="Check if the version of system.data.linq.dll is greater than or equal to 4.0.30319.2000" test_ref="oval:org.mitre.oval:tst:81757"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment=".net 4.5/vista/server 2008/win 7/server 2008 R2/versions">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 4.5 is installed" definition_ref="oval:org.mitre.oval:def:15925"/>
          <criteria operator="OR" comment="either file versions">
            <criterion comment="Check if the version of presentationcore.dll is less than 4.0.30319.18054" test_ref="oval:org.mitre.oval:tst:81455"/>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of presentationcore.dll is less than 4.0.30319.19084" test_ref="oval:org.mitre.oval:tst:81779"/>
              <criterion comment="Check if the version of presentationcore.dll is greater than or equal to 4.0.30319.19000" test_ref="oval:org.mitre.oval:tst:80382"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment=".net 4.5/win 8/server 2012/versions">
          <criteria operator="OR" comment="either os">
            <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
            <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 4.5 is installed" definition_ref="oval:org.mitre.oval:def:15925"/>
          <criteria operator="OR" comment="GDR/LDR">
            <criterion comment="Check if the version of system.configuration.dll is less than 4.0.30319.18053" test_ref="oval:org.mitre.oval:tst:81028"/>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of system.configuration.dll is less than 4.0.30319.19083" test_ref="oval:org.mitre.oval:tst:81485"/>
              <criterion comment="Check if the version of system.configuration.dll is greater than or equal to 4.0.30319.19000" test_ref="oval:org.mitre.oval:tst:81843"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:16860" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability (CVE-2013-3119) - MS13-047</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Vista</platform>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2013-3119" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3119"/>
        <description>Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3114.</description>
        <oval_repository>
          <dates>
            <submitted date="2013-06-13T13:15:31">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-06-13T14:21:12.344-04:00">DRAFT</status_change>
            <status_change date="2013-07-01T04:01:28.142-04:00">INTERIM</status_change>
            <status_change date="2013-07-22T04:01:37.209-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:16860 - extended definitions of OS are without SP checks" date="2014-07-28T17:57:00.076-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T17:59:08.769-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:01:48.954-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 9 + Win 7/R2/Vista/2K8 + vulnerable file versions">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="Vista/2K8/Win7/R2">
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16490" test_ref="oval:org.mitre.oval:tst:81066"/>
            <criteria operator="AND" comment="Check for LDR range">
              <criterion comment="Mshtml.dll version is greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:42899"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20600" test_ref="oval:org.mitre.oval:tst:81015"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + Win 7/R2/Win8/2k12 + vulnerable file versions">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Check for vulnerable OS and respective file versions">
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file version">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16614" test_ref="oval:org.mitre.oval:tst:81263"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.20000" test_ref="oval:org.mitre.oval:tst:80523"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.20719" test_ref="oval:org.mitre.oval:tst:81274"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 8 / 2K12 and vulnerable file version">
              <criteria operator="OR" comment="Win 8 / 2K12">
                <extend_definition comment="Microsoft Windows 8 is installed" definition_ref="oval:org.mitre.oval:def:15732"/>
                <extend_definition comment="Microsoft Windows Server 2012 is installed" definition_ref="oval:org.mitre.oval:def:16359"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16612" test_ref="oval:org.mitre.oval:tst:81283"/>
                <criteria operator="AND" comment="Check for LDR ranges">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.20000" test_ref="oval:org.mitre.oval:tst:80523"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.20717" test_ref="oval:org.mitre.oval:tst:81236"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:16858" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability (CVE-2013-3125) - MS13-047</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <product>Microsoft Internet Explorer 10</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2013-3125" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3125"/>
        <description>Microsoft Internet Explorer 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3118 and CVE-2013-3120.</description>
        <oval_repository>
          <dates>
            <submitted date="2013-06-13T13:15:31">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-06-13T14:21:15.141-04:00">DRAFT</status_change>
            <status_change date="2013-07-01T04:01:27.249-04:00">INTERIM</status_change>
            <status_change date="2013-07-22T04:01:36.421-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:16858 - extended definitions of OS are without SP checks" date="2014-07-28T17:57:00.076-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T17:59:05.429-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:01:48.777-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
        <criteria operator="OR" comment="Check for vulnerable OS and respective file versions">
          <criteria operator="AND" comment="Win 7 / R2 and vulnerable file version">
            <criteria operator="OR" comment="Win 7 / R2">
              <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
              <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
              <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            </criteria>
            <criteria operator="OR" comment="Check for vulnerable version">
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16614" test_ref="oval:org.mitre.oval:tst:81263"/>
              <criteria operator="AND" comment="Check for LDR">
                <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.20000" test_ref="oval:org.mitre.oval:tst:80523"/>
                <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.20719" test_ref="oval:org.mitre.oval:tst:81274"/>
              </criteria>
            </criteria>
          </criteria>
          <criteria operator="AND" comment="Win 8 / 2K12 and vulnerable file version">
            <criteria operator="OR" comment="Win 8 / 2K12">
              <extend_definition comment="Microsoft Windows 8 is installed" definition_ref="oval:org.mitre.oval:def:15732"/>
              <extend_definition comment="Microsoft Windows Server 2012 is installed" definition_ref="oval:org.mitre.oval:def:16359"/>
            </criteria>
            <criteria operator="OR" comment="Check for vulnerable version">
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16612" test_ref="oval:org.mitre.oval:tst:81283"/>
              <criteria operator="AND" comment="Check for LDR ranges">
                <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.20000" test_ref="oval:org.mitre.oval:tst:80523"/>
                <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.20717" test_ref="oval:org.mitre.oval:tst:81236"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:16847" version="4" class="vulnerability">
      <metadata>
        <title>Kernel Information Disclosure Vulnerability - MS13-048</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2013-3136" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3136"/>
        <description>The kernel in Microsoft Windows XP SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, Windows 7 SP1, and Windows 8 on 32-bit platforms does not properly handle unspecified page-fault system calls, which allows local users to obtain sensitive information from kernel memory via a crafted application, aka "Kernel Information Disclosure Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2013-06-13T17:15:43">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-06-13T14:08:49.371-04:00">DRAFT</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:16847 - Corrected platform MS Win Server 8 -> MS Win 8" date="2013-06-24T14:05:00.697-04:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-07-15T04:00:25.269-04:00">INTERIM</status_change>
            <status_change date="2013-08-05T04:00:20.046-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="XP x86 and vulnerable file version">
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <criterion comment="Check if the version of Ntoskrnl.exe is less than 5.1.2600.6387" test_ref="oval:org.mitre.oval:tst:81177"/>
        </criteria>
        <criteria operator="AND" comment="Server 2003 x86 and vulnerable file version">
          <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
          <criterion comment="Check if the version of Ntoskrnl.exe is less than 5.2.3790.5157" test_ref="oval:org.mitre.oval:tst:80294"/>
        </criteria>
        <criteria operator="AND" comment="Vista / 2K8 x86 and vulnerable file version">
          <criteria operator="OR" comment="Vista / 2K8">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of Ntoskrnl.exe is less than 6.0.6002.18832" test_ref="oval:org.mitre.oval:tst:80871"/>
            <criteria operator="AND" comment="Check for LDR range">
              <criterion comment="Check if the version of Ntoskrnl.exe is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80719"/>
              <criterion comment="Check if the version of Ntoskrnl.exe is less than 6.0.6002.23103" test_ref="oval:org.mitre.oval:tst:81140"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 x86 vulnerable file version">
          <extend_definition comment="Microsoft Windows 7 (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12292"/>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of Ntoskrnl.exe is less than 6.1.7601.18147" test_ref="oval:org.mitre.oval:tst:80675"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Ntoskrnl.exe is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:81000"/>
              <criterion comment="Check if the version of Ntoskrnl.exe is less than 6.1.7601.22318" test_ref="oval:org.mitre.oval:tst:80863"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 8 x86 and vulnerable file version">
          <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of Ntoskrnl.exe is less than 6.2.9200.16604" test_ref="oval:org.mitre.oval:tst:80789"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Ntoskrnl.exe is greater than or equal to 6.2.9200.20000" test_ref="oval:org.mitre.oval:tst:80722"/>
              <criterion comment="Check if the version of Ntoskrnl.exe is less than 6.2.9200.20708" test_ref="oval:org.mitre.oval:tst:81243"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:16837" version="3" class="vulnerability">
      <metadata>
        <title>Vulnerability in Windows Print Spooler Components Could Allow Elevation of Privilege - MS13-050</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2013-1339" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1339"/>
        <description>The Print Spooler in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT does not properly manage memory during deletion of printer connections, which allows remote authenticated users to execute arbitrary code via a crafted request, aka "Print Spooler Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2013-06-13T12:49:02">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-06-13T14:08:54.271-04:00">DRAFT</status_change>
            <status_change date="2013-07-01T04:01:23.412-04:00">INTERIM</status_change>
            <status_change date="2013-07-22T04:01:30.753-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="For Microsoft Windows OS and Win32spl.dll version (GDR/LDR)">
          <criteria operator="OR" comment="Microsoft Windows Vista and Windows Server 2008 x64/ia64 is installed">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
            <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
          </criteria>
          <criteria operator="OR" comment="GDR/LDR for Vista and 2008">
            <criterion comment="Check if the file version of Win32spl.dll is less than 6.0.6002.18832" test_ref="oval:org.mitre.oval:tst:81212"/>
            <criteria operator="AND" comment="LDR for">
              <criterion comment="Check if the version of Win32spl.dll is greater than or equal to 6.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80807"/>
              <criterion comment="Check if the file version of Win32spl.dll is less than 6.0.6002.23103" test_ref="oval:org.mitre.oval:tst:81294"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="For Microsoft Windows OS Base and Win32spl.dll version (GDR/LDR)">
          <criteria operator="OR" comment="For Microsoft Windows 7 / Server 2008 R2 x86/x64/ia64 SP1 is installed">
            <extend_definition comment="Microsoft Windows 7 (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12292"/>
            <extend_definition comment="Microsoft Windows 7 x64 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12627"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12567"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12583"/>
          </criteria>
          <criteria operator="OR" comment="GDR/LDR for 7 and R2 SP1">
            <criterion comment="Check if the file version of Win32spl.dll is less than 6.1.7601.18142" test_ref="oval:org.mitre.oval:tst:81130"/>
            <criteria operator="AND" comment="LDR for 7 and R2 SP1">
              <criterion comment="Check if the version of Win32spl.dll is greater than or equal to 6.1.7601.22000" test_ref="oval:org.mitre.oval:tst:80835"/>
              <criterion comment="Check if the file version of Win32spl.dll is less than 6.1.7601.22311" test_ref="oval:org.mitre.oval:tst:81138"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="For Microsoft Windows OS and Win32spl.dll version (GDR/LDR)">
          <criteria operator="OR" comment="For Microsoft Windows 8 and Windows Server 2012 x86/x64 is installed">
            <extend_definition comment="Microsoft Windows 8 is installed" definition_ref="oval:org.mitre.oval:def:15732"/>
            <extend_definition comment="Microsoft Windows Server 2012 is installed" definition_ref="oval:org.mitre.oval:def:16359"/>
          </criteria>
          <criteria operator="OR" comment="GDR/LDR for 8 and 2012">
            <criterion comment="Check if the file version of Win32spl.dll is less than 6.2.9200.16598" test_ref="oval:org.mitre.oval:tst:80997"/>
            <criteria operator="AND" comment="LDR for 8 and 2012">
              <criterion comment="Check if the file version of Win32spl.dll is greater than or equal to or equal to 6.2.9200.20000" test_ref="oval:org.mitre.oval:tst:81131"/>
              <criterion comment="Check if the file version of Win32spl.dll is less than 6.2.9200.20702" test_ref="oval:org.mitre.oval:tst:81053"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:16824" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability (CVE-2013-3113) - MS13-047</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2013-3113" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3113"/>
        <description>Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3112, CVE-2013-3121, CVE-2013-3139, and CVE-2013-3142.</description>
        <oval_repository>
          <dates>
            <submitted date="2013-06-13T13:15:31">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-06-13T14:21:09.870-04:00">DRAFT</status_change>
            <status_change date="2013-07-01T04:01:20.824-04:00">INTERIM</status_change>
            <status_change date="2013-07-22T04:01:27.470-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:16824 - extended definitions of OS are without SP checks" date="2014-07-28T17:57:00.076-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T17:59:07.131-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:01:48.502-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + Win XP/2K3 + vulnerable file versions">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="Check for vulnerable OS and respective file versions">
            <criteria operator="AND" comment="XP X86 and vulnerable file version">
              <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
              <criterion comment="Check if the version of mshtml.dll is less than 6.0.2900.6391" test_ref="oval:org.mitre.oval:tst:81194"/>
            </criteria>
            <criteria operator="AND" comment="XP X64 / 2K3 and vulnerable file version">
              <criteria operator="OR" comment="XP X64 / 2K3">
                <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5161" test_ref="oval:org.mitre.oval:tst:81056"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 7 + Win XP/2K3/Vista/2K8 + vulnerable file versions">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="Check for vulnerable OS and respective file versions">
            <criteria operator="AND" comment="XP/2K3 and vulnerable file versions">
              <criteria operator="OR" comment="XP / 2K3">
                <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
                <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21337" test_ref="oval:org.mitre.oval:tst:81097"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2K8 and vulnerable file versions">
              <criteria operator="OR" comment="Vista / 2K8">
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.18837" test_ref="oval:org.mitre.oval:tst:81234"/>
                <criteria operator="AND" comment="Check for LDR range">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23109" test_ref="oval:org.mitre.oval:tst:81167"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + Win XP/2K3/Vista/2K8/Win7/R2 + vulnerable file versions">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="Check for vulnerable OS and respective file versions">
            <criteria operator="AND" comment="XP/2K3 and vulnerable file versions">
              <criteria operator="OR" comment="XP / 2K3">
                <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
                <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23501" test_ref="oval:org.mitre.oval:tst:80741"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2K8 and vulnerable file versions">
              <criteria operator="OR" comment="Vista / 2K8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19437" test_ref="oval:org.mitre.oval:tst:81287"/>
                <criteria operator="AND" comment="Check for LDR range">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23501" test_ref="oval:org.mitre.oval:tst:80741"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18156" test_ref="oval:org.mitre.oval:tst:81108"/>
                <criteria operator="AND" comment="Check for LDR range">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22326" test_ref="oval:org.mitre.oval:tst:81049"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + Win 7/R2/Vista/2K8 + vulnerable file versions">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="Vista/2K8/Win7/R2">
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16490" test_ref="oval:org.mitre.oval:tst:81066"/>
            <criteria operator="AND" comment="Check for LDR range">
              <criterion comment="Mshtml.dll version is greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:42899"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20600" test_ref="oval:org.mitre.oval:tst:81015"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + Win 7/R2/Win8/2k12 + vulnerable file versions">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Check for vulnerable OS and respective file versions">
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file version">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16614" test_ref="oval:org.mitre.oval:tst:81263"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.20000" test_ref="oval:org.mitre.oval:tst:80523"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.20719" test_ref="oval:org.mitre.oval:tst:81274"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 8 / 2K12 and vulnerable file version">
              <criteria operator="OR" comment="Win 8 / 2K12">
                <extend_definition comment="Microsoft Windows 8 is installed" definition_ref="oval:org.mitre.oval:def:15732"/>
                <extend_definition comment="Microsoft Windows Server 2012 is installed" definition_ref="oval:org.mitre.oval:def:16359"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16612" test_ref="oval:org.mitre.oval:tst:81283"/>
                <criteria operator="AND" comment="Check for LDR ranges">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.20000" test_ref="oval:org.mitre.oval:tst:80523"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.20717" test_ref="oval:org.mitre.oval:tst:81236"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:16815" version="5" class="vulnerability">
      <metadata>
        <title>Memory corruption vulnerability in Internet Explorer - CVE-2013-3146 (MS13-055)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <product>Microsoft Internet Explorer 10</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2013-3146" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3146"/>
        <description>Microsoft Internet Explorer 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3152.</description>
        <oval_repository>
          <dates>
            <submitted date="2013-07-12T12:43:10">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-07-12T16:13:18.977-04:00">DRAFT</status_change>
            <status_change date="2013-07-29T04:00:50.676-04:00">INTERIM</status_change>
            <status_change date="2013-08-19T04:01:46.677-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:16815 - extended definitions of OS are without SP checks" date="2014-07-28T17:59:00.295-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T18:01:21.607-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:01:48.086-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
        <criteria operator="OR" comment="Win 7 / R2">
          <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
          <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
          <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          <extend_definition comment="Microsoft Windows 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:14914"/>
          <extend_definition comment="Microsoft Windows 8 (x64) is installed" definition_ref="oval:org.mitre.oval:def:15571"/>
          <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
        </criteria>
        <criteria operator="OR" comment="Check for vulnerable version">
          <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16635" test_ref="oval:org.mitre.oval:tst:81840"/>
          <criteria operator="AND" comment="Check for LDR">
            <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.20000" test_ref="oval:org.mitre.oval:tst:80523"/>
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.20742" test_ref="oval:org.mitre.oval:tst:81835"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:16778" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability (CVE-2013-3120) - MS13-047</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <product>Microsoft Internet Explorer 10</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2013-3120" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3120"/>
        <description>Microsoft Internet Explorer 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3118 and CVE-2013-3125.</description>
        <oval_repository>
          <dates>
            <submitted date="2013-06-13T13:15:31">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-06-13T14:21:12.757-04:00">DRAFT</status_change>
            <status_change date="2013-07-01T04:01:16.164-04:00">INTERIM</status_change>
            <status_change date="2013-07-22T04:01:20.133-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:16778 - extended definitions of OS are without SP checks" date="2014-07-28T17:57:00.076-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T17:59:06.841-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:01:47.950-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
        <criteria operator="OR" comment="Check for vulnerable OS and respective file versions">
          <criteria operator="AND" comment="Win 7 / R2 and vulnerable file version">
            <criteria operator="OR" comment="Win 7 / R2">
              <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
              <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
              <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            </criteria>
            <criteria operator="OR" comment="Check for vulnerable version">
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16614" test_ref="oval:org.mitre.oval:tst:81263"/>
              <criteria operator="AND" comment="Check for LDR">
                <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.20000" test_ref="oval:org.mitre.oval:tst:80523"/>
                <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.20719" test_ref="oval:org.mitre.oval:tst:81274"/>
              </criteria>
            </criteria>
          </criteria>
          <criteria operator="AND" comment="Win 8 / 2K12 and vulnerable file version">
            <criteria operator="OR" comment="Win 8 / 2K12">
              <extend_definition comment="Microsoft Windows 8 is installed" definition_ref="oval:org.mitre.oval:def:15732"/>
              <extend_definition comment="Microsoft Windows Server 2012 is installed" definition_ref="oval:org.mitre.oval:def:16359"/>
            </criteria>
            <criteria operator="OR" comment="Check for vulnerable version">
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16612" test_ref="oval:org.mitre.oval:tst:81283"/>
              <criteria operator="AND" comment="Check for LDR ranges">
                <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.20000" test_ref="oval:org.mitre.oval:tst:80523"/>
                <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.20717" test_ref="oval:org.mitre.oval:tst:81236"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:16763" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability (CVE-2013-3114) - MS13-047</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Vista</platform>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2013-3114" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3114"/>
        <description>Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3119.</description>
        <oval_repository>
          <dates>
            <submitted date="2013-06-13T13:15:31">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-06-13T14:21:10.710-04:00">DRAFT</status_change>
            <status_change date="2013-07-01T04:01:13.803-04:00">INTERIM</status_change>
            <status_change date="2013-07-22T04:01:18.269-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:16763 - extended definitions of OS are without SP checks" date="2014-07-28T17:57:00.076-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T17:59:08.057-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:01:47.265-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 9 + Win 7/R2/Vista/2K8 + vulnerable file versions">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="Vista/2K8/Win7/R2">
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16490" test_ref="oval:org.mitre.oval:tst:81066"/>
            <criteria operator="AND" comment="Check for LDR range">
              <criterion comment="Mshtml.dll version is greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:42899"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20600" test_ref="oval:org.mitre.oval:tst:81015"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + Win 7/R2/Win8/2k12 + vulnerable file versions">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Check for vulnerable OS and respective file versions">
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file version">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16614" test_ref="oval:org.mitre.oval:tst:81263"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.20000" test_ref="oval:org.mitre.oval:tst:80523"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.20719" test_ref="oval:org.mitre.oval:tst:81274"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 8 / 2K12 and vulnerable file version">
              <criteria operator="OR" comment="Win 8 / 2K12">
                <extend_definition comment="Microsoft Windows 8 is installed" definition_ref="oval:org.mitre.oval:def:15732"/>
                <extend_definition comment="Microsoft Windows Server 2012 is installed" definition_ref="oval:org.mitre.oval:def:16359"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16612" test_ref="oval:org.mitre.oval:tst:81283"/>
                <criteria operator="AND" comment="Check for LDR ranges">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.20000" test_ref="oval:org.mitre.oval:tst:80523"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.20717" test_ref="oval:org.mitre.oval:tst:81236"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:16741" version="5" class="vulnerability">
      <metadata>
        <title>Mircosoft .NET Framework authentication bypass vulnerability - (CVE-2013-1337) MS13-040</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <product>Microsoft .NET Framework 4.5</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2013-1337" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1337"/>
        <description>Microsoft .NET Framework 4.5 does not properly create policy requirements for custom Windows Communication Foundation (WCF) endpoint authentication in certain situations involving passwords over HTTPS, which allows remote attackers to bypass authentication by sending queries to an endpoint, aka "Authentication Bypass Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2013-05-17T11:39:12">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-05-21T11:58:18.223-04:00">DRAFT</status_change>
            <status_change date="2013-06-10T04:01:32.680-04:00">INTERIM</status_change>
            <status_change date="2013-07-01T04:01:10.654-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:16741 - extended definitions of OS are without SP checks" date="2014-07-28T17:29:00.723-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T17:34:31.398-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:01:46.864-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="Microsoft .NET Framework 4.5 is installed" definition_ref="oval:org.mitre.oval:def:15925"/>
        <criteria operator="OR" comment="Check for vulnerable file version">
          <criteria operator="AND" comment="Check for vulnerable OS/file version">
            <criteria operator="OR" comment="Check for vulnerable OS">
              <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
              <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
              <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
              <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
              <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
              <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            </criteria>
            <criteria operator="OR" comment="Check for LDR/GDR">
              <criterion comment="Check if version of System.Security.dll is less than 4.0.30319.18038" test_ref="oval:org.mitre.oval:tst:81011"/>
              <criteria operator="AND" comment="Check for LDR">
                <criterion comment="Check if version of System.Security.dll is greater than or equal to 4.0.30319.19000" test_ref="oval:org.mitre.oval:tst:81085"/>
                <criterion comment="Check if version of System.Security.dll is less than 4.0.30319.19057" test_ref="oval:org.mitre.oval:tst:81186"/>
              </criteria>
            </criteria>
          </criteria>
          <criteria operator="AND" comment="Check for vulnerable file version">
            <criteria operator="OR" comment="Check for vulnerable OS">
              <extend_definition comment="Microsoft Windows 8 is installed" definition_ref="oval:org.mitre.oval:def:15732"/>
              <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
            </criteria>
            <criteria operator="OR" comment="Check for LDR/GDR">
              <criterion comment="Check if version of System.Security.dll is less than 4.0.30319.18039" test_ref="oval:org.mitre.oval:tst:80937"/>
              <criteria operator="AND" comment="Check for LDR">
                <criterion comment="Check if version of System.Security.dll is greater than or equal to 4.0.30319.19000" test_ref="oval:org.mitre.oval:tst:81085"/>
                <criterion comment="Check if version of System.Security.dll is less than 4.0.30319.19058" test_ref="oval:org.mitre.oval:tst:81172"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:16708" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability (CVE-2013-3111) - MS13-047</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2013-3111" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3111"/>
        <description>Microsoft Internet Explorer 8 through 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3123.</description>
        <oval_repository>
          <dates>
            <submitted date="2013-06-13T13:15:31">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-06-13T14:21:09.261-04:00">DRAFT</status_change>
            <status_change date="2013-07-01T04:01:04.801-04:00">INTERIM</status_change>
            <status_change date="2013-07-22T04:01:09.479-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:16708 - extended definitions of OS are without SP checks" date="2014-07-28T17:57:00.076-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T17:59:06.240-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:01:45.835-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 8 + Win XP/2K3/Vista/2K8/Win7/R2 + vulnerable file versions">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="Check for vulnerable OS and respective file versions">
            <criteria operator="AND" comment="XP/2K3 and vulnerable file versions">
              <criteria operator="OR" comment="XP / 2K3">
                <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
                <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23501" test_ref="oval:org.mitre.oval:tst:80741"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2K8 and vulnerable file versions">
              <criteria operator="OR" comment="Vista / 2K8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19437" test_ref="oval:org.mitre.oval:tst:81287"/>
                <criteria operator="AND" comment="Check for LDR range">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23501" test_ref="oval:org.mitre.oval:tst:80741"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18156" test_ref="oval:org.mitre.oval:tst:81108"/>
                <criteria operator="AND" comment="Check for LDR range">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22326" test_ref="oval:org.mitre.oval:tst:81049"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + Win 7/R2/Vista/2K8 + vulnerable file versions">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="Vista/2K8/Win7/R2">
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16490" test_ref="oval:org.mitre.oval:tst:81066"/>
            <criteria operator="AND" comment="Check for LDR range">
              <criterion comment="Mshtml.dll version is greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:42899"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20600" test_ref="oval:org.mitre.oval:tst:81015"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + Win 7/R2/Win8/2k12 + vulnerable file versions">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Check for vulnerable OS and respective file versions">
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file version">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16614" test_ref="oval:org.mitre.oval:tst:81263"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.20000" test_ref="oval:org.mitre.oval:tst:80523"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.20719" test_ref="oval:org.mitre.oval:tst:81274"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 8 / 2K12 and vulnerable file version">
              <criteria operator="OR" comment="Win 8 / 2K12">
                <extend_definition comment="Microsoft Windows 8 is installed" definition_ref="oval:org.mitre.oval:def:15732"/>
                <extend_definition comment="Microsoft Windows Server 2012 is installed" definition_ref="oval:org.mitre.oval:def:16359"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16612" test_ref="oval:org.mitre.oval:tst:81283"/>
                <criteria operator="AND" comment="Check for LDR ranges">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.20000" test_ref="oval:org.mitre.oval:tst:80523"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.20717" test_ref="oval:org.mitre.oval:tst:81236"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:16704" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability (CVE-2013-3142) - MS13-047</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2013-3142" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3142"/>
        <description>Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3112, CVE-2013-3113, CVE-2013-3121, and CVE-2013-3139.</description>
        <oval_repository>
          <dates>
            <submitted date="2013-06-13T13:15:31">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-06-13T14:21:16.710-04:00">DRAFT</status_change>
            <status_change date="2013-07-01T04:01:03.637-04:00">INTERIM</status_change>
            <status_change date="2013-07-22T04:01:08.437-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:16704 - extended definitions of OS are without SP checks" date="2014-07-28T17:57:00.076-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T17:59:07.464-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:01:45.545-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + Win XP/2K3 + vulnerable file versions">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="Check for vulnerable OS and respective file versions">
            <criteria operator="AND" comment="XP X86 and vulnerable file version">
              <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
              <criterion comment="Check if the version of mshtml.dll is less than 6.0.2900.6391" test_ref="oval:org.mitre.oval:tst:81194"/>
            </criteria>
            <criteria operator="AND" comment="XP X64 / 2K3 and vulnerable file version">
              <criteria operator="OR" comment="XP X64 / 2K3">
                <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5161" test_ref="oval:org.mitre.oval:tst:81056"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 7 + Win XP/2K3/Vista/2K8 + vulnerable file versions">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="Check for vulnerable OS and respective file versions">
            <criteria operator="AND" comment="XP/2K3 and vulnerable file versions">
              <criteria operator="OR" comment="XP / 2K3">
                <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
                <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21337" test_ref="oval:org.mitre.oval:tst:81097"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2K8 and vulnerable file versions">
              <criteria operator="OR" comment="Vista / 2K8">
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.18837" test_ref="oval:org.mitre.oval:tst:81234"/>
                <criteria operator="AND" comment="Check for LDR range">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23109" test_ref="oval:org.mitre.oval:tst:81167"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + Win XP/2K3/Vista/2K8/Win7/R2 + vulnerable file versions">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="Check for vulnerable OS and respective file versions">
            <criteria operator="AND" comment="XP/2K3 and vulnerable file versions">
              <criteria operator="OR" comment="XP / 2K3">
                <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
                <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23501" test_ref="oval:org.mitre.oval:tst:80741"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2K8 and vulnerable file versions">
              <criteria operator="OR" comment="Vista / 2K8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19437" test_ref="oval:org.mitre.oval:tst:81287"/>
                <criteria operator="AND" comment="Check for LDR range">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23501" test_ref="oval:org.mitre.oval:tst:80741"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18156" test_ref="oval:org.mitre.oval:tst:81108"/>
                <criteria operator="AND" comment="Check for LDR range">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22326" test_ref="oval:org.mitre.oval:tst:81049"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + Win 7/R2/Vista/2K8 + vulnerable file versions">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="Vista/2K8/Win7/R2">
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16490" test_ref="oval:org.mitre.oval:tst:81066"/>
            <criteria operator="AND" comment="Check for LDR range">
              <criterion comment="Mshtml.dll version is greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:42899"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20600" test_ref="oval:org.mitre.oval:tst:81015"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + Win 7/R2/Win8/2k12 + vulnerable file versions">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Check for vulnerable OS and respective file versions">
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file version">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16614" test_ref="oval:org.mitre.oval:tst:81263"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.20000" test_ref="oval:org.mitre.oval:tst:80523"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.20719" test_ref="oval:org.mitre.oval:tst:81274"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 8 / 2K12 and vulnerable file version">
              <criteria operator="OR" comment="Win 8 / 2K12">
                <extend_definition comment="Microsoft Windows 8 is installed" definition_ref="oval:org.mitre.oval:def:15732"/>
                <extend_definition comment="Microsoft Windows Server 2012 is installed" definition_ref="oval:org.mitre.oval:def:16359"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16612" test_ref="oval:org.mitre.oval:tst:81283"/>
                <criteria operator="AND" comment="Check for LDR ranges">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.20000" test_ref="oval:org.mitre.oval:tst:80523"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.20717" test_ref="oval:org.mitre.oval:tst:81236"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:16687" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer Script Debug Vulnerability - CVE-2013-3126 (MS13-047)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Vista</platform>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2013-3126" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3126"/>
        <description>Microsoft Internet Explorer 9 and 10, when script debugging is enabled, does not properly handle objects in memory during the processing of script, which allows remote attackers to execute arbitrary code via a crafted web site, aka "Internet Explorer Script Debug Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2013-06-13T13:15:31">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-06-13T14:21:06.703-04:00">DRAFT</status_change>
            <status_change date="2013-07-01T04:01:00.264-04:00">INTERIM</status_change>
            <status_change date="2013-07-22T04:01:04.608-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:16687 - extended definitions of OS are without SP checks" date="2014-07-28T17:57:00.076-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T17:59:08.994-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:01:45.122-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 9 + Win 7/R2/Vista/2K8 + vulnerable file versions">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="Vista/2K8/Win7/R2">
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16490" test_ref="oval:org.mitre.oval:tst:81066"/>
            <criteria operator="AND" comment="Check for LDR range">
              <criterion comment="Mshtml.dll version is greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:42899"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20600" test_ref="oval:org.mitre.oval:tst:81015"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + Win 7/R2/Win8/2k12 + vulnerable file versions">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Check for vulnerable OS and respective file versions">
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file version">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16614" test_ref="oval:org.mitre.oval:tst:81263"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.20000" test_ref="oval:org.mitre.oval:tst:80523"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.20719" test_ref="oval:org.mitre.oval:tst:81274"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 8 / 2K12 and vulnerable file version">
              <criteria operator="OR" comment="Win 8 / 2K12">
                <extend_definition comment="Microsoft Windows 8 is installed" definition_ref="oval:org.mitre.oval:def:15732"/>
                <extend_definition comment="Microsoft Windows Server 2012 is installed" definition_ref="oval:org.mitre.oval:def:16359"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16612" test_ref="oval:org.mitre.oval:tst:81283"/>
                <criteria operator="AND" comment="Check for LDR ranges">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.20000" test_ref="oval:org.mitre.oval:tst:80523"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.20717" test_ref="oval:org.mitre.oval:tst:81236"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:16662" version="6" class="vulnerability">
      <metadata>
        <title>Internet Explorer Use After Free Vulnerability - CVE-2013-1303 (MS13-028)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2013-1303" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1303"/>
        <description>Use-after-free vulnerability in Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer Use After Free Vulnerability," a different vulnerability than CVE-2013-1304 and CVE-2013-1338.</description>
        <oval_repository>
          <dates>
            <submitted date="2013-04-12T16:37:58">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-04-15T21:20:47.523-04:00">DRAFT</status_change>
            <status_change date="2013-05-06T04:02:37.280-04:00">INTERIM</status_change>
            <status_change date="2013-05-27T04:00:15.896-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:16662 - extended definitions of OS are without SP checks" date="2014-07-28T17:29:00.723-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T17:34:33.425-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:01:44.447-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + Win XP/2K3 + vulnerable file versions">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="Check for vulnerable OS and respective file versions">
            <criteria operator="AND" comment="XP X86 and vulnerable file version">
              <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
              <criterion comment="Check if the version of mshtml.dll is less than 6.0.2900.6357" test_ref="oval:org.mitre.oval:tst:80867"/>
            </criteria>
            <criteria operator="AND" comment="XP X64 / 2K3 and vulnerable file version">
              <criteria operator="OR" comment="XP X64 / 2K3">
                <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5128" test_ref="oval:org.mitre.oval:tst:81060"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 7 + Win XP/2K3/Vista/2K8 + vulnerable file versions">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="Check for vulnerable OS and respective file versions">
            <criteria operator="AND" comment="XP/2K3 and vulnerable file versions">
              <criteria operator="OR" comment="XP / 2K3">
                <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
                <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.17128" test_ref="oval:org.mitre.oval:tst:81067"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Mshtml.dll version is greater than or equal to 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:79995"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21330" test_ref="oval:org.mitre.oval:tst:80369"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Vista/2K8 and vulnerable file versions">
              <criteria operator="OR" comment="Vista / 2K8">
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.18794" test_ref="oval:org.mitre.oval:tst:81029"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Mshtml.dll version is greater than or equal to 7.0.6002.22000" test_ref="oval:org.mitre.oval:tst:79822"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23064" test_ref="oval:org.mitre.oval:tst:80428"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + Win XP/2K3/Vista/2K8 + vulnerable file versions">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="Check for vulnerable OS and respective file versions">
            <criteria operator="AND" comment="XP/2K3/Vista/2K8 and vulnerable file versions">
              <criteria operator="OR" comment="XP/2K3/Vista/2K8">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
                <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19412" test_ref="oval:org.mitre.oval:tst:80874"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23480" test_ref="oval:org.mitre.oval:tst:81055"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win7/R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 is installed" definition_ref="oval:org.mitre.oval:def:12541"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7600.17267" test_ref="oval:org.mitre.oval:tst:80575"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Mshtml.dll version is greater than or equal 8.0.7600.20000" test_ref="oval:org.mitre.oval:tst:10804"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7600.21484" test_ref="oval:org.mitre.oval:tst:80819"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win7 /2008 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win7 /2008 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18106" test_ref="oval:org.mitre.oval:tst:80951"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Mshtml.dll version is greater than or equal to 8.0.7601.21000" test_ref="oval:org.mitre.oval:tst:80043"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22272" test_ref="oval:org.mitre.oval:tst:81068"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + Win 7/R2/Vista/2K8 + vulnerable file versions">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="Vista/2K8/Win7/R2">
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 is installed" definition_ref="oval:org.mitre.oval:def:12541"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16476" test_ref="oval:org.mitre.oval:tst:80899"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Mshtml.dll version is greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:42899"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20586" test_ref="oval:org.mitre.oval:tst:80864"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + Win 7/R2/Win8/2k12 + vulnerable file versions">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win8/2K12/Win7/R2">
            <extend_definition comment="Microsoft Windows 7 is installed" definition_ref="oval:org.mitre.oval:def:12541"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 is installed" definition_ref="oval:org.mitre.oval:def:15732"/>
            <extend_definition comment="Microsoft Windows Server 2012 is installed" definition_ref="oval:org.mitre.oval:def:16359"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16540" test_ref="oval:org.mitre.oval:tst:81111"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.20000" test_ref="oval:org.mitre.oval:tst:80523"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.20644" test_ref="oval:org.mitre.oval:tst:81072"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:16655" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability (CVE-2013-3123) - MS13-047</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2013-3123" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3123"/>
        <description>Microsoft Internet Explorer 8 through 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3111.</description>
        <oval_repository>
          <dates>
            <submitted date="2013-06-13T13:15:31">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-06-13T14:21:14.173-04:00">DRAFT</status_change>
            <status_change date="2013-07-01T04:00:57.699-04:00">INTERIM</status_change>
            <status_change date="2013-07-22T04:01:02.563-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:16655 - extended definitions of OS are without SP checks" date="2014-07-28T17:57:00.076-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T17:59:04.912-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:01:44.172-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 8 + Win XP/2K3/Vista/2K8/Win7/R2 + vulnerable file versions">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="Check for vulnerable OS and respective file versions">
            <criteria operator="AND" comment="XP/2K3 and vulnerable file versions">
              <criteria operator="OR" comment="XP / 2K3">
                <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
                <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23501" test_ref="oval:org.mitre.oval:tst:80741"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2K8 and vulnerable file versions">
              <criteria operator="OR" comment="Vista / 2K8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19437" test_ref="oval:org.mitre.oval:tst:81287"/>
                <criteria operator="AND" comment="Check for LDR range">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23501" test_ref="oval:org.mitre.oval:tst:80741"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18156" test_ref="oval:org.mitre.oval:tst:81108"/>
                <criteria operator="AND" comment="Check for LDR range">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22326" test_ref="oval:org.mitre.oval:tst:81049"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + Win 7/R2/Vista/2K8 + vulnerable file versions">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="Vista/2K8/Win7/R2">
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16490" test_ref="oval:org.mitre.oval:tst:81066"/>
            <criteria operator="AND" comment="Check for LDR range">
              <criterion comment="Mshtml.dll version is greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:42899"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20600" test_ref="oval:org.mitre.oval:tst:81015"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + Win 7/R2/Win8/2k12 + vulnerable file versions">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Check for vulnerable OS and respective file versions">
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file version">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16614" test_ref="oval:org.mitre.oval:tst:81263"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.20000" test_ref="oval:org.mitre.oval:tst:80523"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.20719" test_ref="oval:org.mitre.oval:tst:81274"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 8 / 2K12 and vulnerable file version">
              <criteria operator="OR" comment="Win 8 / 2K12">
                <extend_definition comment="Microsoft Windows 8 is installed" definition_ref="oval:org.mitre.oval:def:15732"/>
                <extend_definition comment="Microsoft Windows Server 2012 is installed" definition_ref="oval:org.mitre.oval:def:16359"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16612" test_ref="oval:org.mitre.oval:tst:81283"/>
                <criteria operator="AND" comment="Check for LDR ranges">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.20000" test_ref="oval:org.mitre.oval:tst:80523"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.20717" test_ref="oval:org.mitre.oval:tst:81236"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:16634" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer removeChild Use After Free Vulnerability - MS13-021</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2013-0094" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0094"/>
        <description>Use-after-free vulnerability in Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer removeChild Use After Free Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2013-03-14T13:32:03">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-03-18T15:00:45.910-04:00">DRAFT</status_change>
            <status_change date="2013-04-08T04:00:41.792-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:17:23.211-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:16634 - extended definitions of OS are without SP checks" date="2014-07-28T17:29:00.723-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T17:34:29.514-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:01:43.682-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE6 and Win XP/2K3 vulnerable version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="XP/2K3 and vulnerable file version">
            <criteria operator="AND" comment="IE6 vuln file + XP(X86)">
              <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
              <criterion comment="Check if the version of mshtml.dll is less than 6.0.2900.6347" test_ref="oval:org.mitre.oval:tst:80785"/>
            </criteria>
            <criteria operator="AND" comment="IE 6 vuln file + XP(x64) + 2K3(all)">
              <criteria operator="OR" comment="2k3(all)/XP(x64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
                <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5120" test_ref="oval:org.mitre.oval:tst:80841"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE7 + XP/2K3/Vista/2K8">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="XP/2K3/Vista/2K8 and vulnerable file version">
            <criteria operator="AND" comment="XP/2K3 and vulnerable file version">
              <criteria operator="OR" comment="XP/2K3">
                <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
                <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.17123" test_ref="oval:org.mitre.oval:tst:80882"/>
                <criteria operator="AND" comment="LDR range">
                  <criterion comment="Mshtml.dll version is greater than or equal to 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:79995"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21325" test_ref="oval:org.mitre.oval:tst:80993"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Vista/2K8 and vulnerable file version">
              <criteria operator="OR" comment="Vista/2K8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.18778" test_ref="oval:org.mitre.oval:tst:80957"/>
                <criteria operator="AND" comment="Check for vulnerable version">
                  <criterion comment="Mshtml.dll version is greater than or equal to 7.0.6002.22000" test_ref="oval:org.mitre.oval:tst:79822"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23032" test_ref="oval:org.mitre.oval:tst:80211"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE8 + XP/2K3/Vista/2K8">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="XP/2K3/Vista/2K8/Win7/R2 and vulnerable file version">
            <criteria operator="AND" comment="XP/2K3/Vista/2K8 and vulnerable file version">
              <criteria operator="OR" comment="XP/2K3/2K8/Vista">
                <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
                <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19403" test_ref="oval:org.mitre.oval:tst:80911"/>
                <criteria operator="AND" comment="Check for LDR range">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23471" test_ref="oval:org.mitre.oval:tst:80850"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win7/R2 and vulnerable file version">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 is installed" definition_ref="oval:org.mitre.oval:def:12541"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7600.17256" test_ref="oval:org.mitre.oval:tst:80631"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Mshtml.dll version is greater than or equal 8.0.7600.20000" test_ref="oval:org.mitre.oval:tst:10804"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7600.21471" test_ref="oval:org.mitre.oval:tst:80771"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win7/R2 and vulnerable file version">
              <criteria operator="OR" comment="Win7/R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18094" test_ref="oval:org.mitre.oval:tst:80981"/>
                <criteria operator="AND" comment="Check for LDR range">
                  <criterion comment="Mshtml.dll version is greater than or equal to 8.0.7601.21000" test_ref="oval:org.mitre.oval:tst:80043"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22258" test_ref="oval:org.mitre.oval:tst:80996"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE9 and Win7/R2/Vista/2K8 and vulnerable file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="Win 7 / R2 / Vista / 2K8">
            <extend_definition comment="Microsoft Windows 7 is installed" definition_ref="oval:org.mitre.oval:def:12541"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16470" test_ref="oval:org.mitre.oval:tst:80891"/>
            <criteria operator="AND" comment="Check for LDR range">
              <criterion comment="Mshtml.dll version is greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:42899"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20580" test_ref="oval:org.mitre.oval:tst:80959"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE10 Win 8 / 2012 and vulnerable file version">
          <criteria operator="OR" comment="Windows 8 / 2012">
            <extend_definition comment="Microsoft Windows 8 is installed" definition_ref="oval:org.mitre.oval:def:15732"/>
            <extend_definition comment="Microsoft Windows Server 2012 is installed" definition_ref="oval:org.mitre.oval:def:16359"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16525" test_ref="oval:org.mitre.oval:tst:80759"/>
            <criteria operator="AND" comment="Check for LDR range">
              <criterion comment="Check if version of vgx.dll is greater than or equal to 10.0.9200.20000" test_ref="oval:org.mitre.oval:tst:80415"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.20630" test_ref="oval:org.mitre.oval:tst:80969"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:16621" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer Use After Free Vulnerability - CVE-2013-1338 (MS13-028)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer 10</product>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2013-1338" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1338"/>
        <description>Use-after-free vulnerability in Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer Use After Free Vulnerability," a different vulnerability than CVE-2013-1303 and CVE-2013-1304.</description>
        <oval_repository>
          <dates>
            <submitted date="2013-05-02T12:12:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-05-06T17:16:29.451-04:00">DRAFT</status_change>
            <status_change date="2013-05-27T04:00:14.175-04:00">INTERIM</status_change>
            <status_change date="2013-06-17T04:00:15.752-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:16621 - extended definitions of OS are without SP checks" date="2014-07-28T17:29:00.723-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T17:34:29.133-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:01:43.398-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + Win XP/2K3 + vulnerable file versions">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="Check for vulnerable OS and respective file versions">
            <criteria operator="AND" comment="XP X86 and vulnerable file version">
              <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
              <criterion comment="Check if the version of mshtml.dll is less than 6.0.2900.6357" test_ref="oval:org.mitre.oval:tst:80867"/>
            </criteria>
            <criteria operator="AND" comment="XP X64 / 2K3 and vulnerable file version">
              <criteria operator="OR" comment="XP X64 / 2K3">
                <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5128" test_ref="oval:org.mitre.oval:tst:81060"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 7 + Win XP/2K3/Vista/2K8 + vulnerable file versions">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="Check for vulnerable OS and respective file versions">
            <criteria operator="AND" comment="XP/2K3 and vulnerable file versions">
              <criteria operator="OR" comment="XP / 2K3">
                <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
                <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.17128" test_ref="oval:org.mitre.oval:tst:81067"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Mshtml.dll version is greater than or equal to 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:79995"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21330" test_ref="oval:org.mitre.oval:tst:80369"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Vista/2K8 and vulnerable file versions">
              <criteria operator="OR" comment="Vista / 2K8">
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.18794" test_ref="oval:org.mitre.oval:tst:81029"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Mshtml.dll version is greater than or equal to 7.0.6002.22000" test_ref="oval:org.mitre.oval:tst:79822"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23064" test_ref="oval:org.mitre.oval:tst:80428"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + Win XP/2K3/Vista/2K8 + vulnerable file versions">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="Check for vulnerable OS and respective file versions">
            <criteria operator="AND" comment="XP/2K3/Vista/2K8 and vulnerable file versions">
              <criteria operator="OR" comment="XP/2K3/Vista/2K8">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
                <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19412" test_ref="oval:org.mitre.oval:tst:80874"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23480" test_ref="oval:org.mitre.oval:tst:81055"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win7/R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 is installed" definition_ref="oval:org.mitre.oval:def:12541"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7600.17267" test_ref="oval:org.mitre.oval:tst:80575"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Mshtml.dll version is greater than or equal 8.0.7600.20000" test_ref="oval:org.mitre.oval:tst:10804"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7600.21484" test_ref="oval:org.mitre.oval:tst:80819"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win7 /2008 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win7 /2008 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18106" test_ref="oval:org.mitre.oval:tst:80951"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Mshtml.dll version is greater than or equal to 8.0.7601.21000" test_ref="oval:org.mitre.oval:tst:80043"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22272" test_ref="oval:org.mitre.oval:tst:81068"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + Win 7/R2/Vista/2K8 + vulnerable file versions">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="Vista/2K8/Win7/R2">
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows 7 is installed" definition_ref="oval:org.mitre.oval:def:12541"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16476" test_ref="oval:org.mitre.oval:tst:80899"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Mshtml.dll version is greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:42899"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20586" test_ref="oval:org.mitre.oval:tst:80864"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + Win 7/R2/Win8/2k12 + vulnerable file versions">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win8/2K12/Win7/R2">
            <extend_definition comment="Microsoft Windows 7 is installed" definition_ref="oval:org.mitre.oval:def:12541"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 is installed" definition_ref="oval:org.mitre.oval:def:15732"/>
            <extend_definition comment="Microsoft Windows Server 2012 is installed" definition_ref="oval:org.mitre.oval:def:16359"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16540" test_ref="oval:org.mitre.oval:tst:81111"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.20000" test_ref="oval:org.mitre.oval:tst:80523"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.20644" test_ref="oval:org.mitre.oval:tst:81072"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:16596" version="5" class="vulnerability">
      <metadata>
        <title>Callback Function Vulnerability - MS13-024</title>
        <affected family="windows">
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft SharePoint Foundation 2010</product>
          <product>Microsoft SharePoint Server 2010</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2013-0080" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0080"/>
        <description>Microsoft SharePoint Server 2010 SP1 and SharePoint Foundation 2010 SP1 allow remote attackers to bypass intended read restrictions for content, and hijack user accounts, via a crafted URL, aka "Callback Function Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2013-03-14T12:59:10">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-03-18T14:52:41.096-04:00">DRAFT</status_change>
            <status_change date="2013-04-08T04:00:41.275-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:17:19.717-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:1390 - November 2014 bulletins." date="2014-11-17T17:25:00.386-05:00">
              <contributor organization="SecPod Technologies">Kumarswamy S</contributor>
            </modified>
            <status_change date="2014-11-17T17:29:49.752-05:00">INTERIM</status_change>
            <status_change date="2014-12-08T04:00:13.034-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="Check if the version of Onfda.dll is less than 14.0.6134.5000" test_ref="oval:org.mitre.oval:tst:80956"/>
        <extend_definition comment="Microsoft SharePoint Foundation 2010 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:15661"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:16591" version="6" class="vulnerability">
      <metadata>
        <title>Microsoft kernel-mode drivers privilege elevation vulnerability (CVE-2013-1286) - MS13-027</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2013-1286" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1286"/>
        <description>The USB kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, and Windows Server 2012 do not properly handle objects in memory, which allows physically proximate attackers to execute arbitrary code by connecting a crafted USB device, aka "Windows USB Descriptor Vulnerability," a different vulnerability than CVE-2013-1285 and CVE-2013-1287.</description>
        <oval_repository>
          <dates>
            <submitted date="2013-03-14T11:27:19">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-03-18T15:32:22.145-04:00">DRAFT</status_change>
            <status_change date="2013-04-08T04:00:39.900-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:12547 - Submission on Microsoft Bulletin for the month April 2013." date="2013-04-15T21:59:00.487-04:00">
              <contributor organization="SecPod Technologies">Sharath S</contributor>
            </modified>
            <status_change date="2013-05-06T04:02:32.249-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:80438 - contains tests with modified comments and all dependences" date="2014-02-13T12:19:00.287-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-13T12:22:34.288-05:00">INTERIM</status_change>
            <status_change date="2014-03-03T04:00:56.954-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Microsoft Windows XP x86 and vulnerable file version">
          <criterion comment="Check if the version of Usb8023.sys is less than 5.1.2600.6352" test_ref="oval:org.mitre.oval:tst:80974"/>
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
        </criteria>
        <criteria operator="AND" comment="Microsoft Windows 2003/XP x64 and vulnerable file version">
          <criteria operator="OR" comment="Microsoft Windows 2003/XP x64">
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
            <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
          </criteria>
          <criterion comment="Check if the version of Usb8023.sys is less than 5.2.3790.5123" test_ref="oval:org.mitre.oval:tst:80463"/>
        </criteria>
        <criteria operator="AND" comment="Microsoft Windows Vista/2008 and vulnerable file version">
          <criteria operator="OR" comment="Microsoft Windows Vista/2008">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
            <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
          </criteria>
          <criteria operator="OR" comment="vulnerable file version">
            <criterion comment="Check if the version of Usb8023.sys is less than 6.0.6002.18782" test_ref="oval:org.mitre.oval:tst:80512"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Usb8023.sys is greater than or equal to 6.0.6002.22000" test_ref="oval:org.mitre.oval:tst:80528"/>
              <criterion comment="Check if the version of Usb8023.sys is less than 6.0.6002.23038" test_ref="oval:org.mitre.oval:tst:80443"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Microsoft Windows 7/2008 R2 and vulnerable file version">
          <criteria operator="OR" comment="Microsoft Windows 7/2008 R2">
            <extend_definition comment="Microsoft Windows Server 2008 R2 is installed" definition_ref="oval:org.mitre.oval:def:12754"/>
            <extend_definition comment="Microsoft Windows 7 is installed" definition_ref="oval:org.mitre.oval:def:12541"/>
          </criteria>
          <criteria operator="OR" comment="vulnerable file version">
            <criterion comment="Check if the version of Usb8023.sys is less than 6.1.7600.17233" test_ref="oval:org.mitre.oval:tst:80438"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Usb8023.sys is greater than or equal to 6.1.7600.20000" test_ref="oval:org.mitre.oval:tst:80647"/>
              <criterion comment="Check if the version of Usb8023.sys is less than 6.1.7600.21444" test_ref="oval:org.mitre.oval:tst:80854"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Microsoft Windows 7/2008 R2 SP1 and vulnerable file version">
          <criteria operator="OR" comment="Microsoft Windows 7 / 2008 R2 SP1">
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12567"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12583"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12292"/>
            <extend_definition comment="Microsoft Windows 7 x64 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12627"/>
          </criteria>
          <criteria operator="OR" comment="vulnerable file version">
            <criterion comment="Check if the version of Usb8023.sys is less than 6.1.7601.18076" test_ref="oval:org.mitre.oval:tst:80851"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Usb8023.sys is greater than or equal to 6.1.7601.21000" test_ref="oval:org.mitre.oval:tst:80558"/>
              <criterion comment="Check if the version of Usb8023.sys is less than 6.1.7601.22248" test_ref="oval:org.mitre.oval:tst:80934"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Microsoft Windows 8/2012 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 /2012">
            <extend_definition comment="Microsoft Windows 8 is installed" definition_ref="oval:org.mitre.oval:def:15732"/>
            <extend_definition comment="Microsoft Windows Server 2012 is installed" definition_ref="oval:org.mitre.oval:def:16359"/>
          </criteria>
          <criteria operator="OR" comment="vulnerable file version">
            <criterion comment="Check if the version of Usb8023.sys is less than 6.2.9200.16525" test_ref="oval:org.mitre.oval:tst:80988"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Usb8023.sys is greater than or equal to 6.2.9200.20000" test_ref="oval:org.mitre.oval:tst:80999"/>
              <criterion comment="Check if the version of Usb8023.sys is less than 6.2.9200.20630" test_ref="oval:org.mitre.oval:tst:80842"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:16587" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer CMarkupBehaviorContext Use After Free Vulnerability - MS13-021</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2013-0089" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0089"/>
        <description>Use-after-free vulnerability in Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer CMarkupBehaviorContext Use After Free Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2013-03-14T13:32:03">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-03-18T15:00:40.579-04:00">DRAFT</status_change>
            <status_change date="2013-04-08T04:00:38.630-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:17:18.158-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:16587 - extended definitions of OS are without SP checks" date="2014-07-28T17:29:00.723-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T17:34:26.634-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:01:42.880-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE6 and Win XP/2K3 vulnerable version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="XP/2K3 and vulnerable file version">
            <criteria operator="AND" comment="IE6 vuln file + XP(X86)">
              <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
              <criterion comment="Check if the version of mshtml.dll is less than 6.0.2900.6347" test_ref="oval:org.mitre.oval:tst:80785"/>
            </criteria>
            <criteria operator="AND" comment="IE 6 vuln file + XP(x64) + 2K3(all)">
              <criteria operator="OR" comment="2k3(all)/XP(x64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
                <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5120" test_ref="oval:org.mitre.oval:tst:80841"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE7 + XP/2K3/Vista/2K8">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="XP/2K3/Vista/2K8 and vulnerable file version">
            <criteria operator="AND" comment="XP/2K3 and vulnerable file version">
              <criteria operator="OR" comment="XP/2K3">
                <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
                <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.17123" test_ref="oval:org.mitre.oval:tst:80882"/>
                <criteria operator="AND" comment="LDR range">
                  <criterion comment="Mshtml.dll version is greater than or equal to 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:79995"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21325" test_ref="oval:org.mitre.oval:tst:80993"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Vista/2K8 and vulnerable file version">
              <criteria operator="OR" comment="Vista/2K8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.18778" test_ref="oval:org.mitre.oval:tst:80957"/>
                <criteria operator="AND" comment="Check for vulnerable version">
                  <criterion comment="Mshtml.dll version is greater than or equal to 7.0.6002.22000" test_ref="oval:org.mitre.oval:tst:79822"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23032" test_ref="oval:org.mitre.oval:tst:80211"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE8 + XP/2K3/Vista/2K8">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="XP/2K3/Vista/2K8/Win7/R2 and vulnerable file version">
            <criteria operator="AND" comment="XP/2K3/Vista/2K8 and vulnerable file version">
              <criteria operator="OR" comment="XP/2K3/2K8/Vista">
                <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
                <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19403" test_ref="oval:org.mitre.oval:tst:80911"/>
                <criteria operator="AND" comment="Check for LDR range">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23471" test_ref="oval:org.mitre.oval:tst:80850"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win7/R2 and vulnerable file version">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 is installed" definition_ref="oval:org.mitre.oval:def:12541"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7600.17256" test_ref="oval:org.mitre.oval:tst:80631"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Mshtml.dll version is greater than or equal 8.0.7600.20000" test_ref="oval:org.mitre.oval:tst:10804"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7600.21471" test_ref="oval:org.mitre.oval:tst:80771"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win7/R2 and vulnerable file version">
              <criteria operator="OR" comment="Win7/R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18094" test_ref="oval:org.mitre.oval:tst:80981"/>
                <criteria operator="AND" comment="Check for LDR range">
                  <criterion comment="Mshtml.dll version is greater than or equal to 8.0.7601.21000" test_ref="oval:org.mitre.oval:tst:80043"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22258" test_ref="oval:org.mitre.oval:tst:80996"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE9 and Win7/R2/Vista/2K8 and vulnerable file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="Win 7 / R2 / Vista / 2K8">
            <extend_definition comment="Microsoft Windows 7 is installed" definition_ref="oval:org.mitre.oval:def:12541"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16470" test_ref="oval:org.mitre.oval:tst:80891"/>
            <criteria operator="AND" comment="Check for LDR range">
              <criterion comment="Mshtml.dll version is greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:42899"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20580" test_ref="oval:org.mitre.oval:tst:80959"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE10 Win 8 / 2012 and vulnerable file version">
          <criteria operator="OR" comment="Windows 8 / 2012">
            <extend_definition comment="Microsoft Windows 8 is installed" definition_ref="oval:org.mitre.oval:def:15732"/>
            <extend_definition comment="Microsoft Windows Server 2012 is installed" definition_ref="oval:org.mitre.oval:def:16359"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16525" test_ref="oval:org.mitre.oval:tst:80759"/>
            <criteria operator="AND" comment="Check for LDR range">
              <criterion comment="Check if version of vgx.dll is greater than or equal to 10.0.9200.20000" test_ref="oval:org.mitre.oval:tst:80415"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.20630" test_ref="oval:org.mitre.oval:tst:80969"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:16583" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer OnResize Use After Free Vulnerability - MS13-021</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2013-0087" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0087"/>
        <description>Use-after-free vulnerability in Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer OnResize Use After Free Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2013-03-14T13:32:03">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-03-18T15:00:38.160-04:00">DRAFT</status_change>
            <status_change date="2013-04-08T04:00:37.175-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:17:17.158-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:16583 - extended definitions of OS are without SP checks" date="2014-07-28T17:29:00.723-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T17:34:27.022-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:01:42.432-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE6 and Win XP/2K3 vulnerable version">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="XP/2K3 and vulnerable file version">
            <criteria operator="AND" comment="IE6 vuln file + XP(X86)">
              <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
              <criterion comment="Check if the version of mshtml.dll is less than 6.0.2900.6347" test_ref="oval:org.mitre.oval:tst:80785"/>
            </criteria>
            <criteria operator="AND" comment="IE 6 vuln file + XP(x64) + 2K3(all)">
              <criteria operator="OR" comment="2k3(all)/XP(x64)">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
                <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5120" test_ref="oval:org.mitre.oval:tst:80841"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE7 + XP/2K3/Vista/2K8">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="XP/2K3/Vista/2K8 and vulnerable file version">
            <criteria operator="AND" comment="XP/2K3 and vulnerable file version">
              <criteria operator="OR" comment="XP/2K3">
                <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
                <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.17123" test_ref="oval:org.mitre.oval:tst:80882"/>
                <criteria operator="AND" comment="LDR range">
                  <criterion comment="Mshtml.dll version is greater than or equal to 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:79995"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21325" test_ref="oval:org.mitre.oval:tst:80993"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Vista/2K8 and vulnerable file version">
              <criteria operator="OR" comment="Vista/2K8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.18778" test_ref="oval:org.mitre.oval:tst:80957"/>
                <criteria operator="AND" comment="Check for vulnerable version">
                  <criterion comment="Mshtml.dll version is greater than or equal to 7.0.6002.22000" test_ref="oval:org.mitre.oval:tst:79822"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23032" test_ref="oval:org.mitre.oval:tst:80211"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE8 + XP/2K3/Vista/2K8">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="XP/2K3/Vista/2K8/Win7/R2 and vulnerable file version">
            <criteria operator="AND" comment="XP/2K3/Vista/2K8 and vulnerable file version">
              <criteria operator="OR" comment="XP/2K3/2K8/Vista">
                <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
                <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19403" test_ref="oval:org.mitre.oval:tst:80911"/>
                <criteria operator="AND" comment="Check for LDR range">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23471" test_ref="oval:org.mitre.oval:tst:80850"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win7/R2 and vulnerable file version">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 is installed" definition_ref="oval:org.mitre.oval:def:12541"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7600.17256" test_ref="oval:org.mitre.oval:tst:80631"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Mshtml.dll version is greater than or equal 8.0.7600.20000" test_ref="oval:org.mitre.oval:tst:10804"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7600.21471" test_ref="oval:org.mitre.oval:tst:80771"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win7/R2 and vulnerable file version">
              <criteria operator="OR" comment="Win7/R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18094" test_ref="oval:org.mitre.oval:tst:80981"/>
                <criteria operator="AND" comment="Check for LDR range">
                  <criterion comment="Mshtml.dll version is greater than or equal to 8.0.7601.21000" test_ref="oval:org.mitre.oval:tst:80043"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22258" test_ref="oval:org.mitre.oval:tst:80996"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE9 and Win7/R2/Vista/2K8 and vulnerable file version">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="Win 7 / R2 / Vista / 2K8">
            <extend_definition comment="Microsoft Windows 7 is installed" definition_ref="oval:org.mitre.oval:def:12541"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16470" test_ref="oval:org.mitre.oval:tst:80891"/>
            <criteria operator="AND" comment="Check for LDR range">
              <criterion comment="Mshtml.dll version is greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:42899"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20580" test_ref="oval:org.mitre.oval:tst:80959"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE10 Win 8 / 2012 and vulnerable file version">
          <criteria operator="OR" comment="Windows 8 / 2012">
            <extend_definition comment="Microsoft Windows 8 is installed" definition_ref="oval:org.mitre.oval:def:15732"/>
            <extend_definition comment="Microsoft Windows Server 2012 is installed" definition_ref="oval:org.mitre.oval:def:16359"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16525" test_ref="oval:org.mitre.oval:tst:80759"/>
            <criteria operator="AND" comment="Check for LDR range">
              <criterion comment="Check if version of vgx.dll is greater than or equal to 10.0.9200.20000" test_ref="oval:org.mitre.oval:tst:80415"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.20630" test_ref="oval:org.mitre.oval:tst:80969"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:16575" version="7" class="vulnerability">
      <metadata>
        <title>Microsoft Windows Kernel-Mode Driver privilege elevation vulnerability (CVE-2013-1292) - MS13-036</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Vista</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2013-1292" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1292"/>
        <description>Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT allows local users to gain privileges via a crafted application that leverages improper handling of objects in memory, aka "Win32k Race Condition Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2013-04-10T11:39:28">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-04-15T21:55:29.516-04:00">DRAFT</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:12547 - Submission on Microsoft Bulletin for the month April 2013." date="2013-04-15T21:59:00.487-04:00">
              <contributor organization="SecPod Technologies">Sharath S</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:def:16575 - revised bulletin MS13-036 to check for file ntfs.sys version." date="2013-04-24T16:00:00.259-04:00">
              <contributor organization="SecPod Technologies">Bhavya K</contributor>
            </modified>
            <status_change date="2013-05-13T04:00:49.017-04:00">INTERIM</status_change>
            <status_change date="2013-06-03T04:03:15.435-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:5160 - contains tests with modified comments and all dependences" date="2014-02-13T12:19:00.287-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-13T12:22:58.177-05:00">INTERIM</status_change>
            <status_change date="2014-03-03T04:00:56.554-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="vista/server 2008/version">
          <criteria operator="OR" comment="vista/server 2008">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
            <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
          </criteria>
          <criteria operator="OR" comment="either files">
            <criteria operator="OR" comment="gdr/ldr">
              <criterion comment="Check if the version of win32k.sys is less than 6.0.6002.18800" test_ref="oval:org.mitre.oval:tst:80966"/>
              <criteria operator="AND" comment="ldr range">
                <criterion comment="Check if the version of win32k.sys is less than 6.0.6002.23071" test_ref="oval:org.mitre.oval:tst:81096"/>
                <criterion comment="the version of win32k.sys is greater than 6.0.6002.22000" test_ref="oval:org.mitre.oval:tst:10124"/>
              </criteria>
            </criteria>
            <criteria operator="OR" comment="gdr/ldr">
              <criterion comment="Check if the version of Ntfs.sys is less than 6.0.6002.18799" test_ref="oval:org.mitre.oval:tst:80856"/>
              <criteria operator="AND" comment="ldr range">
                <criterion comment="Check if the version of Ntfs.sys is less than 6.0.6002.23070" test_ref="oval:org.mitre.oval:tst:81063"/>
                <criterion comment="Check if the version of ntfs.sys is greater than or equal to 6.0.6002.22000" test_ref="oval:org.mitre.oval:tst:80915"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="win 7/server 2008 R2/version">
          <criteria operator="OR" comment="win 7/server 2008 R2">
            <extend_definition comment="Microsoft Windows 7 is installed" definition_ref="oval:org.mitre.oval:def:12541"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 is installed" definition_ref="oval:org.mitre.oval:def:12754"/>
          </criteria>
          <criteria operator="OR" comment="either files">
            <criteria operator="OR" comment="gdr/ldr">
              <criterion comment="Check if the version of win32k.sys is less than 6.1.7600.17266" test_ref="oval:org.mitre.oval:tst:80954"/>
              <criteria operator="AND" comment="ldr range">
                <criterion comment="Check if the version of win32k.sys is less than 6.1.7600.21482" test_ref="oval:org.mitre.oval:tst:80612"/>
                <criterion comment="the version of win32k.sys is greater than or equal to 6.1.7600.20000" test_ref="oval:org.mitre.oval:tst:27587"/>
              </criteria>
            </criteria>
            <criteria operator="OR" comment="gdr/ldr">
              <criterion comment="Check if the version of Ntfs.sys is less than 6.1.7600.17281" test_ref="oval:org.mitre.oval:tst:80412"/>
              <criteria operator="AND" comment="ldr range">
                <criterion comment="Check if the version of Ntfs.sys is less than 6.1.7600.21499" test_ref="oval:org.mitre.oval:tst:80923"/>
                <criterion comment="Check if ntfs.sys file version is greater than or equal to 6.1.7600.20000" test_ref="oval:org.mitre.oval:tst:80991"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="win 7 sp1/server 2008 R2 sp1/version">
          <criteria operator="OR" comment="win 7 sp1/server 2008 R2 sp1">
            <extend_definition comment="Microsoft Windows 7 (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12292"/>
            <extend_definition comment="Microsoft Windows 7 x64 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12627"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12567"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12583"/>
          </criteria>
          <criteria operator="OR" comment="either files">
            <criteria operator="OR" comment="gdr/ldr">
              <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.18105" test_ref="oval:org.mitre.oval:tst:80868"/>
              <criteria operator="AND" comment="ldr range">
                <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.22271" test_ref="oval:org.mitre.oval:tst:81044"/>
                <criterion comment="the version of win32k.sys is greater than or equal to 6.1.7601.21000" test_ref="oval:org.mitre.oval:tst:42715"/>
              </criteria>
            </criteria>
            <criteria operator="OR" comment="gdr/ldr">
              <criterion comment="Check if the version of Ntfs.sys is less than 6.1.7601.18127" test_ref="oval:org.mitre.oval:tst:80972"/>
              <criteria operator="AND" comment="ldr range">
                <criterion comment="Check if the version of Ntfs.sys is less than 6.1.7601.22297" test_ref="oval:org.mitre.oval:tst:80455"/>
                <criterion comment="Check if ntfs.sys file version is greater than or equal to 6.1.7601.21000" test_ref="oval:org.mitre.oval:tst:80979"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="win 8/server 2012/version">
          <criteria operator="OR" comment="win 8/server 2012">
            <extend_definition comment="Microsoft Windows 8 is installed" definition_ref="oval:org.mitre.oval:def:15732"/>
            <extend_definition comment="Microsoft Windows Server 2012 is installed" definition_ref="oval:org.mitre.oval:def:16359"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.16559" test_ref="oval:org.mitre.oval:tst:80866"/>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.20663" test_ref="oval:org.mitre.oval:tst:80960"/>
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.2.9200.20000" test_ref="oval:org.mitre.oval:tst:80697"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:16563" version="7" class="vulnerability">
      <metadata>
        <title>Microsoft Windows Kernel-Mode Driver privilege elevation vulnerability (CVE-2013-1283) - MS13-036</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2013-1283" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1283"/>
        <description>Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT allows local users to gain privileges via a crafted application that leverages improper handling of objects in memory, aka "Win32k Race Condition Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2013-04-10T11:39:28">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-04-15T21:55:28.153-04:00">DRAFT</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:12547 - Submission on Microsoft Bulletin for the month April 2013." date="2013-04-15T21:59:00.487-04:00">
              <contributor organization="SecPod Technologies">Sharath S</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:def:16563 - revised bulletin MS13-036 to check for file ntfs.sys version." date="2013-04-24T16:00:00.259-04:00">
              <contributor organization="SecPod Technologies">Bhavya K</contributor>
            </modified>
            <status_change date="2013-05-13T04:00:47.330-04:00">INTERIM</status_change>
            <status_change date="2013-06-03T04:03:13.618-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:5160 - contains tests with modified comments and all dependences" date="2014-02-13T12:19:00.287-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-13T12:22:55.776-05:00">INTERIM</status_change>
            <status_change date="2014-03-03T04:00:56.085-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="win xp/version">
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <criterion comment="Check if the version of win32k.sys is less than 5.1.2600.6364" test_ref="oval:org.mitre.oval:tst:80883"/>
        </criteria>
        <criteria operator="AND" comment="server 2003/xp sp2/versions">
          <criteria operator="OR" comment="server 2003/xp sp2">
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
          </criteria>
          <criterion comment="Check if the version of win32k.sys is less than 5.2.3790.5134" test_ref="oval:org.mitre.oval:tst:80601"/>
        </criteria>
        <criteria operator="AND" comment="vista/server 2008/version">
          <criteria operator="OR" comment="vista/server 2008">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
            <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
          </criteria>
          <criteria operator="OR" comment="either files">
            <criteria operator="OR" comment="gdr/ldr">
              <criterion comment="Check if the version of win32k.sys is less than 6.0.6002.18800" test_ref="oval:org.mitre.oval:tst:80966"/>
              <criteria operator="AND" comment="ldr range">
                <criterion comment="Check if the version of win32k.sys is less than 6.0.6002.23071" test_ref="oval:org.mitre.oval:tst:81096"/>
                <criterion comment="the version of win32k.sys is greater than 6.0.6002.22000" test_ref="oval:org.mitre.oval:tst:10124"/>
              </criteria>
            </criteria>
            <criteria operator="OR" comment="gdr/ldr">
              <criterion comment="Check if the version of Ntfs.sys is less than 6.0.6002.18799" test_ref="oval:org.mitre.oval:tst:80856"/>
              <criteria operator="AND" comment="ldr range">
                <criterion comment="Check if the version of Ntfs.sys is less than 6.0.6002.23070" test_ref="oval:org.mitre.oval:tst:81063"/>
                <criterion comment="Check if the version of ntfs.sys is greater than or equal to 6.0.6002.22000" test_ref="oval:org.mitre.oval:tst:80915"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="win 7/server 2008 R2/version">
          <criteria operator="OR" comment="win 7/server 2008 R2">
            <extend_definition comment="Microsoft Windows 7 is installed" definition_ref="oval:org.mitre.oval:def:12541"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 is installed" definition_ref="oval:org.mitre.oval:def:12754"/>
          </criteria>
          <criteria operator="OR" comment="either files">
            <criteria operator="OR" comment="gdr/ldr">
              <criterion comment="Check if the version of win32k.sys is less than 6.1.7600.17266" test_ref="oval:org.mitre.oval:tst:80954"/>
              <criteria operator="AND" comment="ldr range">
                <criterion comment="Check if the version of win32k.sys is less than 6.1.7600.21482" test_ref="oval:org.mitre.oval:tst:80612"/>
                <criterion comment="the version of win32k.sys is greater than or equal to 6.1.7600.20000" test_ref="oval:org.mitre.oval:tst:27587"/>
              </criteria>
            </criteria>
            <criteria operator="OR" comment="gdr/ldr">
              <criterion comment="Check if the version of Ntfs.sys is less than 6.1.7600.17281" test_ref="oval:org.mitre.oval:tst:80412"/>
              <criteria operator="AND" comment="ldr range">
                <criterion comment="Check if the version of Ntfs.sys is less than 6.1.7600.21499" test_ref="oval:org.mitre.oval:tst:80923"/>
                <criterion comment="Check if ntfs.sys file version is greater than or equal to 6.1.7600.20000" test_ref="oval:org.mitre.oval:tst:80991"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="win 7 sp1/server 2008 R2 sp1/version">
          <criteria operator="OR" comment="win 7 sp1/server 2008 R2 sp1">
            <extend_definition comment="Microsoft Windows 7 (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12292"/>
            <extend_definition comment="Microsoft Windows 7 x64 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12627"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12567"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12583"/>
          </criteria>
          <criteria operator="OR" comment="either files">
            <criteria operator="OR" comment="gdr/ldr">
              <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.18105" test_ref="oval:org.mitre.oval:tst:80868"/>
              <criteria operator="AND" comment="ldr range">
                <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.22271" test_ref="oval:org.mitre.oval:tst:81044"/>
                <criterion comment="the version of win32k.sys is greater than or equal to 6.1.7601.21000" test_ref="oval:org.mitre.oval:tst:42715"/>
              </criteria>
            </criteria>
            <criteria operator="OR" comment="gdr/ldr">
              <criterion comment="Check if the version of Ntfs.sys is less than 6.1.7601.18127" test_ref="oval:org.mitre.oval:tst:80972"/>
              <criteria operator="AND" comment="ldr range">
                <criterion comment="Check if the version of Ntfs.sys is less than 6.1.7601.22297" test_ref="oval:org.mitre.oval:tst:80455"/>
                <criterion comment="Check if ntfs.sys file version is greater than or equal to 6.1.7601.21000" test_ref="oval:org.mitre.oval:tst:80979"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="win 8/server 2012/version">
          <criteria operator="OR" comment="win 8/server 2012">
            <extend_definition comment="Microsoft Windows 8 is installed" definition_ref="oval:org.mitre.oval:def:15732"/>
            <extend_definition comment="Microsoft Windows Server 2012 is installed" definition_ref="oval:org.mitre.oval:def:16359"/>
          </criteria>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.16559" test_ref="oval:org.mitre.oval:tst:80866"/>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.20663" test_ref="oval:org.mitre.oval:tst:80960"/>
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.2.9200.20000" test_ref="oval:org.mitre.oval:tst:80697"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:16559" version="7" class="vulnerability">
      <metadata>
        <title>Microsoft .NET Framework Common Language Runtime spoofing vulnerability - (CVE-2013-1336) MS13-040</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <product>Microsoft .NET Framework 2.0</product>
          <product>Microsoft .NET Framework 3.5</product>
          <product>Microsoft .NET Framework 3.5.1</product>
          <product>Microsoft .NET Framework 4.0</product>
          <product>Microsoft .NET Framework 4.5</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2013-1336" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1336"/>
        <description>The Common Language Runtime (CLR) in Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, and 4.5 does not properly check signatures, which allows remote attackers to make undetected changes to signed XML documents via unspecified vectors that preserve signature validity, aka "XML Digital Signature Spoofing Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2013-05-17T11:39:12">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-05-21T11:58:17.439-04:00">DRAFT</status_change>
            <status_change date="2013-06-10T04:01:13.882-04:00">INTERIM</status_change>
            <status_change date="2013-07-01T04:00:50.846-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:16559 - .NET Framework 3.5.1 instead .NET Framework 3.5 in Windows 8 and Windows Server 2012" date="2014-03-31T14:51:00.481-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-03-31T14:53:47.630-04:00">INTERIM</status_change>
            <status_change date="2014-04-21T04:00:15.195-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:16559 - extended definitions of OS are without SP checks" date="2014-07-28T17:29:00.723-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T17:34:33.728-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:01:42.038-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Check for vulnerable .NET Framework 2.0 and file version">
          <extend_definition comment="Microsoft .NET Framework 2.0 Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6158"/>
          <criteria operator="OR" comment="Check for vulnerable .NET Framework 2.0">
            <criteria operator="AND" comment="Check for vulnerable file version">
              <criteria operator="OR" comment="Check for vulnerable OS">
                <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
                <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
              </criteria>
              <criteria operator="OR" comment="Check for LDR/GDR">
                <criterion comment="Check if version of System.Security.dll is less than 2.0.50727.3646" test_ref="oval:org.mitre.oval:tst:81200"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if System.Security.dll version is greater than or equal to 2.0.50727.4000" test_ref="oval:org.mitre.oval:tst:81021"/>
                  <criterion comment="Check if version of System.Security.dll is less than 2.0.50727.7019" test_ref="oval:org.mitre.oval:tst:81045"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Check for vulnerable file version">
              <criteria operator="OR" comment="Check for vulnerable OS">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for LDR/GDR">
                <criterion comment="Check if version of System.Security.dll is less than 2.0.50727.4237" test_ref="oval:org.mitre.oval:tst:81150"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if System.Security.dll version is greater than or equal to 2.0.50727.5000" test_ref="oval:org.mitre.oval:tst:80869"/>
                  <criterion comment="Check if version of System.Security.dll is less than 2.0.50727.7018" test_ref="oval:org.mitre.oval:tst:80894"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Check for vulnerable .NET Framework 3.5 and file version">
          <extend_definition comment="Microsoft .NET Framework 3.5 SP1 is installed" definition_ref="oval:org.mitre.oval:def:12542"/>
          <criteria operator="OR" comment="Check for vulnerable OS">
            <extend_definition comment="Microsoft Windows 8 is installed" definition_ref="oval:org.mitre.oval:def:15732"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="Check for LDR/GDR">
            <criterion comment="Check if version of System.Security.dll is less than 2.0.50727.6404" test_ref="oval:org.mitre.oval:tst:80712"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if version of System.Security.dll is greater than or equal to 2.0.50727.7000" test_ref="oval:org.mitre.oval:tst:80839"/>
              <criterion comment="Check if version of System.Security.dll is less than 2.0.50727.7018" test_ref="oval:org.mitre.oval:tst:80894"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Check for vulnerable .NET Framework 3.5.1 and file version">
          <extend_definition comment="Microsoft .NET Framework 3.5 SP1 is installed" definition_ref="oval:org.mitre.oval:def:12542"/>
          <criteria operator="OR" comment="Check for vulnerable OS">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="Check for LDR/GDR">
            <criterion comment="Check if version of System.Security.dll is less than 2.0.50727.5469" test_ref="oval:org.mitre.oval:tst:80227"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if version of System.Security.dll is greater than or equal to 2.0.50727.7000" test_ref="oval:org.mitre.oval:tst:80839"/>
              <criterion comment="Check if version of System.Security.dll is less than 2.0.50727.7018" test_ref="oval:org.mitre.oval:tst:80894"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Check for vulnerable .NET Framework 4.0 and file version">
          <extend_definition comment="Microsoft .NET Framework 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6749"/>
          <criteria operator="OR" comment="Check for vulnerable OS">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="Check for LDR/GDR">
            <criterion comment="Check if version of System.Security.dll is less than 4.0.30319.1004" test_ref="oval:org.mitre.oval:tst:80823"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if version of System.Security.dll is greater than or equal to 4.0.30319.2000" test_ref="oval:org.mitre.oval:tst:80978"/>
              <criterion comment="Check if version of System.Security.dll is less than 4.0.30319.2006" test_ref="oval:org.mitre.oval:tst:81037"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Check for vulnerable .NET Framework 4.5 and file version">
          <extend_definition comment="Microsoft .NET Framework 4.5 is installed" definition_ref="oval:org.mitre.oval:def:15925"/>
          <criteria operator="OR" comment="Check for vulnerable file version">
            <criteria operator="AND" comment="Check for vulnerable OS/file version">
              <criteria operator="OR" comment="Check for vulnerable OS">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="Check for LDR/GDR">
                <criterion comment="Check if version of System.Security.dll is less than 4.0.30319.18038" test_ref="oval:org.mitre.oval:tst:81011"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if version of System.Security.dll is greater than or equal to 4.0.30319.19000" test_ref="oval:org.mitre.oval:tst:81085"/>
                  <criterion comment="Check if version of System.Security.dll is less than 4.0.30319.19057" test_ref="oval:org.mitre.oval:tst:81186"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Check for vulnerable file version">
              <criteria operator="OR" comment="Check for vulnerable OS">
                <extend_definition comment="Microsoft Windows 8 is installed" definition_ref="oval:org.mitre.oval:def:15732"/>
                <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
              </criteria>
              <criteria operator="OR" comment="Check for LDR/GDR">
                <criterion comment="Check if version of System.Security.dll is less than 4.0.30319.18039" test_ref="oval:org.mitre.oval:tst:80937"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if version of System.Security.dll is greater than or equal to 4.0.30319.19000" test_ref="oval:org.mitre.oval:tst:81085"/>
                  <criterion comment="Check if version of System.Security.dll is less than 4.0.30319.19058" test_ref="oval:org.mitre.oval:tst:81172"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:16517" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability (CVE-2013-3139) - MS13-047</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2013-3139" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3139"/>
        <description>Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3112, CVE-2013-3113, CVE-2013-3121, and CVE-2013-3142.</description>
        <oval_repository>
          <dates>
            <submitted date="2013-06-13T13:15:31">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-06-13T14:21:15.437-04:00">DRAFT</status_change>
            <status_change date="2013-07-01T04:00:47.135-04:00">INTERIM</status_change>
            <status_change date="2013-07-22T04:00:52.893-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:16517 - extended definitions of OS are without SP checks" date="2014-07-28T17:57:00.076-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T17:59:06.605-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:01:40.950-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + Win XP/2K3 + vulnerable file versions">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="Check for vulnerable OS and respective file versions">
            <criteria operator="AND" comment="XP X86 and vulnerable file version">
              <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
              <criterion comment="Check if the version of mshtml.dll is less than 6.0.2900.6391" test_ref="oval:org.mitre.oval:tst:81194"/>
            </criteria>
            <criteria operator="AND" comment="XP X64 / 2K3 and vulnerable file version">
              <criteria operator="OR" comment="XP X64 / 2K3">
                <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5161" test_ref="oval:org.mitre.oval:tst:81056"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 7 + Win XP/2K3/Vista/2K8 + vulnerable file versions">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="Check for vulnerable OS and respective file versions">
            <criteria operator="AND" comment="XP/2K3 and vulnerable file versions">
              <criteria operator="OR" comment="XP / 2K3">
                <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
                <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21337" test_ref="oval:org.mitre.oval:tst:81097"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2K8 and vulnerable file versions">
              <criteria operator="OR" comment="Vista / 2K8">
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.18837" test_ref="oval:org.mitre.oval:tst:81234"/>
                <criteria operator="AND" comment="Check for LDR range">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23109" test_ref="oval:org.mitre.oval:tst:81167"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + Win XP/2K3/Vista/2K8/Win7/R2 + vulnerable file versions">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="Check for vulnerable OS and respective file versions">
            <criteria operator="AND" comment="XP/2K3 and vulnerable file versions">
              <criteria operator="OR" comment="XP / 2K3">
                <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
                <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23501" test_ref="oval:org.mitre.oval:tst:80741"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2K8 and vulnerable file versions">
              <criteria operator="OR" comment="Vista / 2K8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19437" test_ref="oval:org.mitre.oval:tst:81287"/>
                <criteria operator="AND" comment="Check for LDR range">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23501" test_ref="oval:org.mitre.oval:tst:80741"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18156" test_ref="oval:org.mitre.oval:tst:81108"/>
                <criteria operator="AND" comment="Check for LDR range">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22326" test_ref="oval:org.mitre.oval:tst:81049"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + Win 7/R2/Vista/2K8 + vulnerable file versions">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="Vista/2K8/Win7/R2">
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16490" test_ref="oval:org.mitre.oval:tst:81066"/>
            <criteria operator="AND" comment="Check for LDR range">
              <criterion comment="Mshtml.dll version is greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:42899"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20600" test_ref="oval:org.mitre.oval:tst:81015"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + Win 7/R2/Win8/2k12 + vulnerable file versions">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Check for vulnerable OS and respective file versions">
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file version">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16614" test_ref="oval:org.mitre.oval:tst:81263"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.20000" test_ref="oval:org.mitre.oval:tst:80523"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.20719" test_ref="oval:org.mitre.oval:tst:81274"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 8 / 2K12 and vulnerable file version">
              <criteria operator="OR" comment="Win 8 / 2K12">
                <extend_definition comment="Microsoft Windows 8 is installed" definition_ref="oval:org.mitre.oval:def:15732"/>
                <extend_definition comment="Microsoft Windows Server 2012 is installed" definition_ref="oval:org.mitre.oval:def:16359"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16612" test_ref="oval:org.mitre.oval:tst:81283"/>
                <criteria operator="AND" comment="Check for LDR ranges">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.20000" test_ref="oval:org.mitre.oval:tst:80523"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.20717" test_ref="oval:org.mitre.oval:tst:81236"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:16515" version="6" class="vulnerability">
      <metadata>
        <title>Internet Explorer Use After Free Vulnerability - CVE-2013-1304 (MS13-028)</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2013-1304" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1304"/>
        <description>Use-after-free vulnerability in Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer Use After Free Vulnerability," a different vulnerability than CVE-2013-1303 and CVE-2013-1338.</description>
        <oval_repository>
          <dates>
            <submitted date="2013-04-12T16:37:58">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-04-15T21:20:48.459-04:00">DRAFT</status_change>
            <status_change date="2013-05-06T04:02:30.733-04:00">INTERIM</status_change>
            <status_change date="2013-05-27T04:00:09.994-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:16515 - extended definitions of OS are without SP checks" date="2014-07-28T17:29:00.723-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T17:34:31.041-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:01:40.625-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + Win XP/2K3 + vulnerable file versions">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="Check for vulnerable OS and respective file versions">
            <criteria operator="AND" comment="XP X86 and vulnerable file version">
              <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
              <criterion comment="Check if the version of mshtml.dll is less than 6.0.2900.6357" test_ref="oval:org.mitre.oval:tst:80867"/>
            </criteria>
            <criteria operator="AND" comment="XP X64 / 2K3 and vulnerable file version">
              <criteria operator="OR" comment="XP X64 / 2K3">
                <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5128" test_ref="oval:org.mitre.oval:tst:81060"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 7 + Win XP/2K3/Vista/2K8 + vulnerable file versions">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="Check for vulnerable OS and respective file versions">
            <criteria operator="AND" comment="XP/2K3 and vulnerable file versions">
              <criteria operator="OR" comment="XP / 2K3">
                <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
                <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.17128" test_ref="oval:org.mitre.oval:tst:81067"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Mshtml.dll version is greater than or equal to 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:79995"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21330" test_ref="oval:org.mitre.oval:tst:80369"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Vista/2K8 and vulnerable file versions">
              <criteria operator="OR" comment="Vista / 2K8">
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.18794" test_ref="oval:org.mitre.oval:tst:81029"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Mshtml.dll version is greater than or equal to 7.0.6002.22000" test_ref="oval:org.mitre.oval:tst:79822"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23064" test_ref="oval:org.mitre.oval:tst:80428"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + Win XP/2K3/Vista/2K8 + vulnerable file versions">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="Check for vulnerable OS and respective file versions">
            <criteria operator="AND" comment="XP/2K3/Vista/2K8 and vulnerable file versions">
              <criteria operator="OR" comment="XP/2K3/Vista/2K8">
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
                <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19412" test_ref="oval:org.mitre.oval:tst:80874"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23480" test_ref="oval:org.mitre.oval:tst:81055"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win7/R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 is installed" definition_ref="oval:org.mitre.oval:def:12541"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7600.17267" test_ref="oval:org.mitre.oval:tst:80575"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Mshtml.dll version is greater than or equal 8.0.7600.20000" test_ref="oval:org.mitre.oval:tst:10804"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7600.21484" test_ref="oval:org.mitre.oval:tst:80819"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win7/2008 R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7/ 2008 R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18106" test_ref="oval:org.mitre.oval:tst:80951"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Mshtml.dll version is greater than or equal to 8.0.7601.21000" test_ref="oval:org.mitre.oval:tst:80043"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22272" test_ref="oval:org.mitre.oval:tst:81068"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + Win 7/R2/Vista/2K8 + vulnerable file versions">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="Vista/2K8/Win7/R2">
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16476" test_ref="oval:org.mitre.oval:tst:80899"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Mshtml.dll version is greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:42899"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20586" test_ref="oval:org.mitre.oval:tst:80864"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + Win 7/R2/Win8/2k12 + vulnerable file versions">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win8/2K12/Win7/R2">
            <extend_definition comment="Microsoft Windows 7 is installed" definition_ref="oval:org.mitre.oval:def:12541"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows 8 is installed" definition_ref="oval:org.mitre.oval:def:15732"/>
            <extend_definition comment="Microsoft Windows Server 2012 is installed" definition_ref="oval:org.mitre.oval:def:16359"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16540" test_ref="oval:org.mitre.oval:tst:81111"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.20000" test_ref="oval:org.mitre.oval:tst:80523"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.20644" test_ref="oval:org.mitre.oval:tst:81072"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:16504" version="7" class="vulnerability">
      <metadata>
        <title>Microsoft Windows Kernel-Mode Driver privilege elevation vulnerability (CVE-2013-1291) - MS13-036</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2013-1291" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1291"/>
        <description>win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, Windows 7 Gold and SP1, and Windows 8 allows local users to cause a denial of service (reboot) via a crafted OpenType font, aka "OpenType Font Parsing Vulnerability" or "Win32k Font Parsing Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2013-04-10T11:39:28">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-04-15T21:55:29.091-04:00">DRAFT</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:12547 - Submission on Microsoft Bulletin for the month April 2013." date="2013-04-15T21:59:00.487-04:00">
              <contributor organization="SecPod Technologies">Sharath S</contributor>
            </modified>
            <modified comment="EDITED oval:org.mitre.oval:def:16504 - revised bulletin MS13-036 to check for file ntfs.sys version." date="2013-04-24T16:00:00.259-04:00">
              <contributor organization="SecPod Technologies">Bhavya K</contributor>
            </modified>
            <status_change date="2013-05-13T04:00:36.436-04:00">INTERIM</status_change>
            <status_change date="2013-06-03T04:03:02.600-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:5160 - contains tests with modified comments and all dependences" date="2014-02-13T12:19:00.287-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-13T12:23:00.295-05:00">INTERIM</status_change>
            <status_change date="2014-03-03T04:00:55.696-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="win xp/version">
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <criterion comment="Check if the version of win32k.sys is less than 5.1.2600.6364" test_ref="oval:org.mitre.oval:tst:80883"/>
        </criteria>
        <criteria operator="AND" comment="server 2003/xp sp2/versions">
          <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
          <criterion comment="Check if the version of win32k.sys is less than 5.2.3790.5134" test_ref="oval:org.mitre.oval:tst:80601"/>
        </criteria>
        <criteria operator="AND" comment="vista/server 2008/version">
          <criteria operator="OR" comment="vista/server 2008">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
          </criteria>
          <criteria operator="OR" comment="either files">
            <criteria operator="OR" comment="gdr/ldr">
              <criterion comment="Check if the version of win32k.sys is less than 6.0.6002.18800" test_ref="oval:org.mitre.oval:tst:80966"/>
              <criteria operator="AND" comment="ldr range">
                <criterion comment="Check if the version of win32k.sys is less than 6.0.6002.23071" test_ref="oval:org.mitre.oval:tst:81096"/>
                <criterion comment="the version of win32k.sys is greater than 6.0.6002.22000" test_ref="oval:org.mitre.oval:tst:10124"/>
              </criteria>
            </criteria>
            <criteria operator="OR" comment="gdr/ldr">
              <criterion comment="Check if the version of Ntfs.sys is less than 6.0.6002.18799" test_ref="oval:org.mitre.oval:tst:80856"/>
              <criteria operator="AND" comment="ldr range">
                <criterion comment="Check if the version of Ntfs.sys is less than 6.0.6002.23070" test_ref="oval:org.mitre.oval:tst:81063"/>
                <criterion comment="Check if the version of ntfs.sys is greater than or equal to 6.0.6002.22000" test_ref="oval:org.mitre.oval:tst:80915"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="win 7/version">
          <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
          <criteria operator="OR" comment="either files">
            <criteria operator="OR" comment="gdr/ldr">
              <criterion comment="Check if the version of win32k.sys is less than 6.1.7600.17266" test_ref="oval:org.mitre.oval:tst:80954"/>
              <criteria operator="AND" comment="ldr range">
                <criterion comment="Check if the version of win32k.sys is less than 6.1.7600.21482" test_ref="oval:org.mitre.oval:tst:80612"/>
                <criterion comment="the version of win32k.sys is greater than or equal to 6.1.7600.20000" test_ref="oval:org.mitre.oval:tst:27587"/>
              </criteria>
            </criteria>
            <criteria operator="OR" comment="gdr/ldr">
              <criterion comment="Check if the version of Ntfs.sys is less than 6.1.7600.17281" test_ref="oval:org.mitre.oval:tst:80412"/>
              <criteria operator="AND" comment="ldr range">
                <criterion comment="Check if the version of Ntfs.sys is less than 6.1.7600.21499" test_ref="oval:org.mitre.oval:tst:80923"/>
                <criterion comment="Check if ntfs.sys file version is greater than or equal to 6.1.7600.20000" test_ref="oval:org.mitre.oval:tst:80991"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="win 7 sp1/version">
          <extend_definition comment="Microsoft Windows 7 (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12292"/>
          <criteria operator="OR" comment="either files">
            <criteria operator="OR" comment="gdr/ldr">
              <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.18105" test_ref="oval:org.mitre.oval:tst:80868"/>
              <criteria operator="AND" comment="ldr range">
                <criterion comment="Check if the version of win32k.sys is less than 6.1.7601.22271" test_ref="oval:org.mitre.oval:tst:81044"/>
                <criterion comment="the version of win32k.sys is greater than or equal to 6.1.7601.21000" test_ref="oval:org.mitre.oval:tst:42715"/>
              </criteria>
            </criteria>
            <criteria operator="OR" comment="gdr/ldr">
              <criterion comment="Check if the version of Ntfs.sys is less than 6.1.7601.18127" test_ref="oval:org.mitre.oval:tst:80972"/>
              <criteria operator="AND" comment="ldr range">
                <criterion comment="Check if the version of Ntfs.sys is less than 6.1.7601.22297" test_ref="oval:org.mitre.oval:tst:80455"/>
                <criterion comment="Check if ntfs.sys file version is greater than or equal to 6.1.7601.21000" test_ref="oval:org.mitre.oval:tst:80979"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="win 8/version">
          <extend_definition comment="Microsoft Windows 8 is installed" definition_ref="oval:org.mitre.oval:def:15732"/>
          <criteria operator="OR" comment="gdr/ldr">
            <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.16559" test_ref="oval:org.mitre.oval:tst:80866"/>
            <criteria operator="AND" comment="ldr range">
              <criterion comment="Check if the version of win32k.sys is less than 6.2.9200.20663" test_ref="oval:org.mitre.oval:tst:80960"/>
              <criterion comment="Check if the version of Win32k.sys is greater than or equal to 6.2.9200.20000" test_ref="oval:org.mitre.oval:tst:80697"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:16498" version="6" class="vulnerability">
      <metadata>
        <title>Microsoft kernel-mode drivers privilege elevation vulnerability (CVE-2013-1287) - MS13-027</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2013-1287" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1287"/>
        <description>The USB kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, and Windows Server 2012 do not properly handle objects in memory, which allows physically proximate attackers to execute arbitrary code by connecting a crafted USB device, aka "Windows USB Descriptor Vulnerability," a different vulnerability than CVE-2013-1285 and CVE-2013-1286.</description>
        <oval_repository>
          <dates>
            <submitted date="2013-03-14T11:27:19">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-03-18T15:32:22.794-04:00">DRAFT</status_change>
            <status_change date="2013-04-08T04:00:31.718-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:12547 - Submission on Microsoft Bulletin for the month April 2013." date="2013-04-15T21:59:00.487-04:00">
              <contributor organization="SecPod Technologies">Sharath S</contributor>
            </modified>
            <status_change date="2013-05-06T04:02:25.890-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:80438 - contains tests with modified comments and all dependences" date="2014-02-13T12:19:00.287-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-02-13T12:22:34.182-05:00">INTERIM</status_change>
            <status_change date="2014-03-03T04:00:55.327-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Microsoft Windows XP x86 and vulnerable file version">
          <criterion comment="Check if the version of Usb8023.sys is less than 5.1.2600.6352" test_ref="oval:org.mitre.oval:tst:80974"/>
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
        </criteria>
        <criteria operator="AND" comment="Microsoft Windows 2003/XP x64 and vulnerable file version">
          <criteria operator="OR" comment="Microsoft Windows 2003/XP x64">
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
            <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
          </criteria>
          <criterion comment="Check if the version of Usb8023.sys is less than 5.2.3790.5123" test_ref="oval:org.mitre.oval:tst:80463"/>
        </criteria>
        <criteria operator="AND" comment="Microsoft Windows Vista/2008 and vulnerable file version">
          <criteria operator="OR" comment="Microsoft Windows Vista/2008">
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
            <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
          </criteria>
          <criteria operator="OR" comment="vulnerable file version">
            <criterion comment="Check if the version of Usb8023.sys is less than 6.0.6002.18782" test_ref="oval:org.mitre.oval:tst:80512"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Usb8023.sys is greater than or equal to 6.0.6002.22000" test_ref="oval:org.mitre.oval:tst:80528"/>
              <criterion comment="Check if the version of Usb8023.sys is less than 6.0.6002.23038" test_ref="oval:org.mitre.oval:tst:80443"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Microsoft Windows 7/2008 R2 and vulnerable file version">
          <criteria operator="OR" comment="Microsoft Windows 7/2008 R2">
            <extend_definition comment="Microsoft Windows Server 2008 R2 is installed" definition_ref="oval:org.mitre.oval:def:12754"/>
            <extend_definition comment="Microsoft Windows 7 is installed" definition_ref="oval:org.mitre.oval:def:12541"/>
          </criteria>
          <criteria operator="OR" comment="vulnerable file version">
            <criterion comment="Check if the version of Usb8023.sys is less than 6.1.7600.17233" test_ref="oval:org.mitre.oval:tst:80438"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Usb8023.sys is greater than or equal to 6.1.7600.20000" test_ref="oval:org.mitre.oval:tst:80647"/>
              <criterion comment="Check if the version of Usb8023.sys is less than 6.1.7600.21444" test_ref="oval:org.mitre.oval:tst:80854"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Microsoft Windows 7/2008 R2 SP1 and vulnerable file version">
          <criteria operator="OR" comment="Microsoft Windows 7 / 2008 R2 SP1">
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12567"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12583"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12292"/>
            <extend_definition comment="Microsoft Windows 7 x64 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12627"/>
          </criteria>
          <criteria operator="OR" comment="vulnerable file version">
            <criterion comment="Check if the version of Usb8023.sys is less than 6.1.7601.18076" test_ref="oval:org.mitre.oval:tst:80851"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Usb8023.sys is greater than or equal to 6.1.7601.21000" test_ref="oval:org.mitre.oval:tst:80558"/>
              <criterion comment="Check if the version of Usb8023.sys is less than 6.1.7601.22248" test_ref="oval:org.mitre.oval:tst:80934"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Microsoft Windows 8/2012 and vulnerable file version">
          <criteria operator="OR" comment="Win 8 /2012">
            <extend_definition comment="Microsoft Windows 8 is installed" definition_ref="oval:org.mitre.oval:def:15732"/>
            <extend_definition comment="Microsoft Windows Server 2012 is installed" definition_ref="oval:org.mitre.oval:def:16359"/>
          </criteria>
          <criteria operator="OR" comment="vulnerable file version">
            <criterion comment="Check if the version of Usb8023.sys is less than 6.2.9200.16525" test_ref="oval:org.mitre.oval:tst:80988"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of Usb8023.sys is greater than or equal to 6.2.9200.20000" test_ref="oval:org.mitre.oval:tst:80999"/>
              <criterion comment="Check if the version of Usb8023.sys is less than 6.2.9200.20630" test_ref="oval:org.mitre.oval:tst:80842"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:16483" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer vtable use after free vulnerability - MS13-009</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2013-0021" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0021"/>
        <description>Use-after-free vulnerability in Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer vtable Use After Free Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2013-02-15T10:36:24">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-02-15T15:34:18.714-05:00">DRAFT</status_change>
            <status_change date="2013-03-04T04:01:17.871-05:00">INTERIM</status_change>
            <status_change date="2013-03-25T04:00:59.528-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:16483 - extended definitions of OS are without SP checks" date="2014-07-28T17:55:00.859-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T17:57:27.522-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:01:40.086-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 and vulnerable versions">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="Vulnerable OS and respective files">
            <criteria operator="AND" comment="Win XP X86 and vulnerable IE 6">
              <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
              <criterion comment="Check if the version of mshtml.dll is less than 6.0.2900.6332" test_ref="oval:org.mitre.oval:tst:80776"/>
            </criteria>
            <criteria operator="AND" comment="XP X64 / 2K3 and vulnerable IE6">
              <criteria operator="OR" comment="XP X64 / 2K3">
                <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5102" test_ref="oval:org.mitre.oval:tst:80700"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 7 and vulnerable versions">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="Vulnerable OS and respective files">
            <criteria operator="AND" comment="XP/2K3 and vulnerable IE7">
              <criteria operator="OR" comment="XP / 2K3">
                <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
                <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.17122" test_ref="oval:org.mitre.oval:tst:80814"/>
                <criteria operator="AND" comment="Check for LDR range">
                  <criterion comment="Mshtml.dll version is greater than or equal to 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:79995"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21324" test_ref="oval:org.mitre.oval:tst:80808"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Vista/2K8 and vulnerable IE7">
              <criteria operator="OR" comment="Vista / 2K8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.18766" test_ref="oval:org.mitre.oval:tst:80643"/>
                <criteria operator="AND" comment="Check for LDR range">
                  <criterion comment="Mshtml.dll version is greater than or equal to 7.0.6002.22000" test_ref="oval:org.mitre.oval:tst:79822"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23015" test_ref="oval:org.mitre.oval:tst:80452"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 and vulnerable versions">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="Vulnerable OS and respective files">
            <criteria operator="AND" comment="XP/2K3/Vista/2K8 and vulnerable IE 8 version">
              <criteria operator="OR" comment="XP/2K3/Vista/2K8">
                <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
                <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19400" test_ref="oval:org.mitre.oval:tst:80810"/>
                <criteria operator="AND" comment="Check for LDR range">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23468" test_ref="oval:org.mitre.oval:tst:80358"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable IE 8 version">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 is installed" definition_ref="oval:org.mitre.oval:def:12541"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 is installed" definition_ref="oval:org.mitre.oval:def:12754"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7600.17209" test_ref="oval:org.mitre.oval:tst:80045"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Mshtml.dll version is greater than or equal 8.0.7600.20000" test_ref="oval:org.mitre.oval:tst:10804"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7600.21419" test_ref="oval:org.mitre.oval:tst:80804"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable IE 8 version">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18035" test_ref="oval:org.mitre.oval:tst:80702"/>
                <criteria operator="AND" comment="Check for LDR range">
                  <criterion comment="Mshtml.dll version is greater than or equal to 8.0.7601.21000" test_ref="oval:org.mitre.oval:tst:80043"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22199" test_ref="oval:org.mitre.oval:tst:80711"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 and vulnerable OS versions">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="Vista/2K8/Win7/R2">
            <extend_definition comment="Microsoft Windows 7 is installed" definition_ref="oval:org.mitre.oval:def:12541"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16464" test_ref="oval:org.mitre.oval:tst:80834"/>
            <criteria operator="AND" comment="Check for LDR range">
              <criterion comment="Mshtml.dll version is greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:42899"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20573" test_ref="oval:org.mitre.oval:tst:80592"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 and vulnerable OS versions">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 8 / 2012">
            <extend_definition comment="Microsoft Windows 8 is installed" definition_ref="oval:org.mitre.oval:def:15732"/>
            <extend_definition comment="Microsoft Windows Server 2012 is installed" definition_ref="oval:org.mitre.oval:def:16359"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16494" test_ref="oval:org.mitre.oval:tst:80734"/>
            <criteria operator="AND" comment="Check for LDR range">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.20000" test_ref="oval:org.mitre.oval:tst:80523"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.20599" test_ref="oval:org.mitre.oval:tst:79891"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:16477" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer Memory Corruption Vulnerability (CVE-2013-3112) - MS13-047</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer 6</product>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2013-3112" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3112"/>
        <description>Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3113, CVE-2013-3121, CVE-2013-3139, and CVE-2013-3142.</description>
        <oval_repository>
          <dates>
            <submitted date="2013-06-13T13:15:31">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-06-13T14:21:07.925-04:00">DRAFT</status_change>
            <status_change date="2013-07-01T04:00:44.411-04:00">INTERIM</status_change>
            <status_change date="2013-07-22T04:00:48.430-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:16477 - extended definitions of OS are without SP checks" date="2014-07-28T17:57:00.076-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T17:59:04.299-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:01:39.715-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 6 + Win XP/2K3 + vulnerable file versions">
          <extend_definition comment="Microsoft Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criteria operator="OR" comment="Check for vulnerable OS and respective file versions">
            <criteria operator="AND" comment="XP X86 and vulnerable file version">
              <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
              <criterion comment="Check if the version of mshtml.dll is less than 6.0.2900.6391" test_ref="oval:org.mitre.oval:tst:81194"/>
            </criteria>
            <criteria operator="AND" comment="XP X64 / 2K3 and vulnerable file version">
              <criteria operator="OR" comment="XP X64 / 2K3">
                <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 6.0.3790.5161" test_ref="oval:org.mitre.oval:tst:81056"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 7 + Win XP/2K3/Vista/2K8 + vulnerable file versions">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="Check for vulnerable OS and respective file versions">
            <criteria operator="AND" comment="XP/2K3 and vulnerable file versions">
              <criteria operator="OR" comment="XP / 2K3">
                <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
                <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21337" test_ref="oval:org.mitre.oval:tst:81097"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2K8 and vulnerable file versions">
              <criteria operator="OR" comment="Vista / 2K8">
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.18837" test_ref="oval:org.mitre.oval:tst:81234"/>
                <criteria operator="AND" comment="Check for LDR range">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 7.0.6002.23000" test_ref="oval:org.mitre.oval:tst:80815"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23109" test_ref="oval:org.mitre.oval:tst:81167"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 + Win XP/2K3/Vista/2K8/Win7/R2 + vulnerable file versions">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="Check for vulnerable OS and respective file versions">
            <criteria operator="AND" comment="XP/2K3 and vulnerable file versions">
              <criteria operator="OR" comment="XP / 2K3">
                <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
                <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
              </criteria>
              <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23501" test_ref="oval:org.mitre.oval:tst:80741"/>
            </criteria>
            <criteria operator="AND" comment="Vista/2K8 and vulnerable file versions">
              <criteria operator="OR" comment="Vista / 2K8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19437" test_ref="oval:org.mitre.oval:tst:81287"/>
                <criteria operator="AND" comment="Check for LDR range">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23501" test_ref="oval:org.mitre.oval:tst:80741"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file versions">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable versions">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18156" test_ref="oval:org.mitre.oval:tst:81108"/>
                <criteria operator="AND" comment="Check for LDR range">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 8.0.7601.22000" test_ref="oval:org.mitre.oval:tst:81176"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22326" test_ref="oval:org.mitre.oval:tst:81049"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 + Win 7/R2/Vista/2K8 + vulnerable file versions">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="Vista/2K8/Win7/R2">
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable versions">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16490" test_ref="oval:org.mitre.oval:tst:81066"/>
            <criteria operator="AND" comment="Check for LDR range">
              <criterion comment="Mshtml.dll version is greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:42899"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20600" test_ref="oval:org.mitre.oval:tst:81015"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 + Win 7/R2/Win8/2k12 + vulnerable file versions">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Check for vulnerable OS and respective file versions">
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable file version">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16614" test_ref="oval:org.mitre.oval:tst:81263"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.20000" test_ref="oval:org.mitre.oval:tst:80523"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.20719" test_ref="oval:org.mitre.oval:tst:81274"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 8 / 2K12 and vulnerable file version">
              <criteria operator="OR" comment="Win 8 / 2K12">
                <extend_definition comment="Microsoft Windows 8 is installed" definition_ref="oval:org.mitre.oval:def:15732"/>
                <extend_definition comment="Microsoft Windows Server 2012 is installed" definition_ref="oval:org.mitre.oval:def:16359"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16612" test_ref="oval:org.mitre.oval:tst:81283"/>
                <criteria operator="AND" comment="Check for LDR ranges">
                  <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.20000" test_ref="oval:org.mitre.oval:tst:80523"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.20717" test_ref="oval:org.mitre.oval:tst:81236"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:16475" version="7" class="vulnerability">
      <metadata>
        <title>WinForms callback elevation vulnerability in .NET Framework - MS13-015</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <product>Microsoft .NET Framework 2.0</product>
          <product>Microsoft .NET Framework 3.5</product>
          <product>Microsoft .NET Framework 3.5.1</product>
          <product>Microsoft .NET Framework 4.0</product>
          <product>Microsoft .NET Framework 4.5</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2013-0073" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0073"/>
        <description>The Windows Forms (aka WinForms) component in Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, and 4.5 does not properly restrict the privileges of a callback function during object creation, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (XBAP) or (2) a crafted .NET Framework application, aka "WinForms Callback Elevation Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2013-02-15T12:24:48">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-02-15T16:18:57.281-05:00">DRAFT</status_change>
            <status_change date="2013-03-04T04:01:15.852-05:00">INTERIM</status_change>
            <status_change date="2013-03-25T04:00:57.379-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:16475 - .NET Framework 3.5.1 instead .NET Framework 3.5 in Windows 8 and Windows Server 2012" date="2014-03-31T14:51:00.481-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-03-31T14:53:46.453-04:00">INTERIM</status_change>
            <status_change date="2014-04-21T04:00:14.687-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:16475 - extended definitions of OS are without SP checks" date="2014-07-28T17:55:00.859-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T17:57:26.706-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:01:39.317-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Check for vulnerable .NET Framework 2.0 and file version">
          <extend_definition comment="Microsoft .NET Framework 2.0 Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6158"/>
          <criteria operator="OR" comment="Check for vulnerable .NET Framework 2.0">
            <criteria operator="AND" comment="Check for vulnerable file version">
              <criteria operator="OR" comment="Check for vulnerable OS">
                <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
                <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
              </criteria>
              <criteria operator="OR" comment="Check for LDR/GDR">
                <criterion comment="Check if version of System.Windows.Forms.dll is less than 2.0.50727.3645" test_ref="oval:org.mitre.oval:tst:80844"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if version of System.Windows.Forms.dll is greater than or equal to 2.0.50727.7000" test_ref="oval:org.mitre.oval:tst:80848"/>
                  <criterion comment="Check if version of System.Windows.Forms.dll is less than 2.0.50727.7015" test_ref="oval:org.mitre.oval:tst:80881"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Check for vulnerable file version">
              <criteria operator="OR" comment="Check for vulnerable OS">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for LDR/GDR">
                <criterion comment="Check if version of System.Windows.Forms.dll is less than 2.0.50727.4236" test_ref="oval:org.mitre.oval:tst:80204"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if version of System.Windows.Forms.dll is greater than or equal to 2.0.50727.7000" test_ref="oval:org.mitre.oval:tst:80848"/>
                  <criterion comment="Check if version of System.Windows.Forms.dll is less than 2.0.50727.7015" test_ref="oval:org.mitre.oval:tst:80881"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Check for vulnerable .NET Framework 3.5 and file version">
          <extend_definition comment="Microsoft .NET Framework 3.5 SP1 is installed" definition_ref="oval:org.mitre.oval:def:12542"/>
          <criteria operator="OR" comment="Check for vulnerable OS">
            <extend_definition comment="Microsoft Windows 8 is installed" definition_ref="oval:org.mitre.oval:def:15732"/>
            <extend_definition comment="Microsoft Windows Server 2012 is installed" definition_ref="oval:org.mitre.oval:def:16359"/>
          </criteria>
          <criteria operator="OR" comment="Check for LDR/GDR">
            <criterion comment="Check if version of system.windows.forms.dll is less than 2.0.50727.6402" test_ref="oval:org.mitre.oval:tst:80887"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if version of System.Windows.Forms.dll is greater than or equal to 2.0.50727.7000" test_ref="oval:org.mitre.oval:tst:80848"/>
              <criterion comment="Check if version of System.Windows.Forms.dll is less than 2.0.50727.7015" test_ref="oval:org.mitre.oval:tst:80881"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Check for vulnerable .NET Framework 3.5.1 and file version">
          <extend_definition comment="Microsoft .NET Framework 3.5 SP1 is installed" definition_ref="oval:org.mitre.oval:def:12542"/>
          <criteria operator="OR" comment="Check for vulnerable file version">
            <criteria operator="AND" comment="Check for vulnerable OS/file version">
              <criteria operator="OR" comment="Check for vulnerable OS">
                <extend_definition comment="Microsoft Windows 7 is installed" definition_ref="oval:org.mitre.oval:def:12541"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for LDR/GDR">
                <criterion comment="Check if version of system.windows.forms.dll is less than 2.0.50727.4986" test_ref="oval:org.mitre.oval:tst:80746"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if version of System.Windows.Forms.dll is greater than or equal to 2.0.50727.7000" test_ref="oval:org.mitre.oval:tst:80848"/>
                  <criterion comment="Check if version of System.Windows.Forms.dll is less than 2.0.50727.7015" test_ref="oval:org.mitre.oval:tst:80881"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Check for vulnerable file version">
              <criteria operator="OR" comment="Check for vulnerable OS">
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
              </criteria>
              <criteria operator="OR" comment="Check for LDR/GDR">
                <criterion comment="Check if version of system.windows.forms.dll is less than 2.0.50727.5468" test_ref="oval:org.mitre.oval:tst:80813"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if version of System.Windows.Forms.dll is greater than or equal to 2.0.50727.7000" test_ref="oval:org.mitre.oval:tst:80848"/>
                  <criterion comment="Check if version of System.Windows.Forms.dll is less than 2.0.50727.7015" test_ref="oval:org.mitre.oval:tst:80881"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Check for vulnerable .NET Framework 4.0 and file version">
          <extend_definition comment="Microsoft .NET Framework 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6749"/>
          <criteria operator="OR" comment="Check for vulnerable OS">
            <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
            <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
            <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
            <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
            <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
            <extend_definition comment="Microsoft Windows 7 is installed" definition_ref="oval:org.mitre.oval:def:12541"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
          </criteria>
          <criteria operator="OR" comment="Check for LDR/GDR">
            <criterion comment="Check if version of System.Windows.Forms.dll is less than 4.0.30319.1002" test_ref="oval:org.mitre.oval:tst:80880"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if version of System.Windows.Forms.dll is greater than or equal to 4.0.30319.2000" test_ref="oval:org.mitre.oval:tst:80817"/>
              <criterion comment="Check if version of System.Windows.Forms.dll is less than 4.0.30319.2003" test_ref="oval:org.mitre.oval:tst:80843"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Check for vulnerable .NET Framework 4.5 and file version">
          <criteria operator="OR" comment="Check for vulnerable file version">
            <criteria operator="AND" comment="Check for vulnerable OS/file version">
              <criteria operator="OR" comment="Check for vulnerable OS">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
              </criteria>
              <criteria operator="OR" comment="Check for LDR/GDR">
                <criterion comment="Check if version of System.Windows.Forms.dll is less than 4.0.30319.18036" test_ref="oval:org.mitre.oval:tst:80846"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if version of System.Windows.Forms.dll is greater than or equal to 4.0.30319.19000" test_ref="oval:org.mitre.oval:tst:80503"/>
                  <criterion comment="Check if version of System.Windows.Forms.dll is less than 4.0.30319.19052" test_ref="oval:org.mitre.oval:tst:80603"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Check for vulnerable file version">
              <criteria operator="OR" comment="Check for vulnerable OS">
                <extend_definition comment="Microsoft Windows 8 is installed" definition_ref="oval:org.mitre.oval:def:15732"/>
                <extend_definition comment="Microsoft Windows Server 2012 is installed" definition_ref="oval:org.mitre.oval:def:16359"/>
              </criteria>
              <criteria operator="OR" comment="Check for LDR/GDR">
                <criterion comment="Check if version of system.windows.forms.dll is less than 4.0.30319.18037" test_ref="oval:org.mitre.oval:tst:80667"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Check if version of System.Windows.Forms.dll is greater than or equal to 4.0.30319.19000" test_ref="oval:org.mitre.oval:tst:80503"/>
                  <criterion comment="Check if version of system.windows.forms.dll is less than 4.0.30319.19053" test_ref="oval:org.mitre.oval:tst:80730"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
          <extend_definition comment="Microsoft .NET Framework 4.5 is installed" definition_ref="oval:org.mitre.oval:def:15925"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:16470" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer CDispNode use after free vulnerability - MS13-009</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2013-0023" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0023"/>
        <description>Use-after-free vulnerability in Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer CDispNode Use After Free Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2013-02-15T10:36:24">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-02-15T15:34:22.589-05:00">DRAFT</status_change>
            <status_change date="2013-03-04T04:01:13.938-05:00">INTERIM</status_change>
            <status_change date="2013-03-25T04:00:54.995-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:16470 - extended definitions of OS are without SP checks" date="2014-07-28T17:55:00.859-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T17:57:26.958-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:01:38.987-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 9 and vulnerable OS versions">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="Vista/2K8/Win7/R2">
            <extend_definition comment="Microsoft Windows 7 is installed" definition_ref="oval:org.mitre.oval:def:12541"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16464" test_ref="oval:org.mitre.oval:tst:80834"/>
            <criteria operator="AND" comment="Check for LDR range">
              <criterion comment="Mshtml.dll version is greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:42899"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20573" test_ref="oval:org.mitre.oval:tst:80592"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 and vulnerable OS versions">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 8 / 2012">
            <extend_definition comment="Microsoft Windows 8 is installed" definition_ref="oval:org.mitre.oval:def:15732"/>
            <extend_definition comment="Microsoft Windows Server 2012 is installed" definition_ref="oval:org.mitre.oval:def:16359"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16494" test_ref="oval:org.mitre.oval:tst:80734"/>
            <criteria operator="AND" comment="Check for LDR range">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.20000" test_ref="oval:org.mitre.oval:tst:80523"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.20599" test_ref="oval:org.mitre.oval:tst:79891"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:16465" version="5" class="vulnerability">
      <metadata>
        <title>Internet Explorer COmWindowProxy use after free vulnerability - MS13-009</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <product>Microsoft Internet Explorer 7</product>
          <product>Microsoft Internet Explorer 8</product>
          <product>Microsoft Internet Explorer 9</product>
          <product>Microsoft Internet Explorer 10</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2013-0019" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0019"/>
        <description>Use-after-free vulnerability in Microsoft Internet Explorer 7 through 10 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer COmWindowProxy Use After Free Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2013-02-15T10:36:24">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-02-15T15:34:20.586-05:00">DRAFT</status_change>
            <status_change date="2013-03-04T04:01:12.478-05:00">INTERIM</status_change>
            <status_change date="2013-03-25T04:00:53.271-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:16465 - extended definitions of OS are without SP checks" date="2014-07-28T17:55:00.859-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T17:57:28.373-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:01:38.696-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IE 7 and vulnerable versions">
          <extend_definition comment="Microsoft Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criteria operator="OR" comment="Vulnerable OS and respective files">
            <criteria operator="AND" comment="XP/2K3 and vulnerable IE7">
              <criteria operator="OR" comment="XP / 2K3">
                <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
                <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Server 2003 (ia64) Gold is installed" definition_ref="oval:org.mitre.oval:def:396"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.17122" test_ref="oval:org.mitre.oval:tst:80814"/>
                <criteria operator="AND" comment="Check for LDR range">
                  <criterion comment="Mshtml.dll version is greater than or equal to 7.0.6000.20000" test_ref="oval:org.mitre.oval:tst:79995"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6000.21324" test_ref="oval:org.mitre.oval:tst:80808"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Vista/2K8 and vulnerable IE7">
              <criteria operator="OR" comment="Vista / 2K8">
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
                <extend_definition comment="Microsoft Windows Server 2008 (ia-64) is installed" definition_ref="oval:org.mitre.oval:def:5667"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.18766" test_ref="oval:org.mitre.oval:tst:80643"/>
                <criteria operator="AND" comment="Check for LDR range">
                  <criterion comment="Mshtml.dll version is greater than or equal to 7.0.6002.22000" test_ref="oval:org.mitre.oval:tst:79822"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 7.0.6002.23015" test_ref="oval:org.mitre.oval:tst:80452"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 8 and vulnerable versions">
          <extend_definition comment="Microsoft Internet Explorer 8 is installed" definition_ref="oval:org.mitre.oval:def:6210"/>
          <criteria operator="OR" comment="Vulnerable OS and respective files">
            <criteria operator="AND" comment="XP/2K3/Vista/2K8 and vulnerable IE 8 version">
              <criteria operator="OR" comment="XP/2K3/Vista/2K8">
                <extend_definition comment="Microsoft Windows XP (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1353"/>
                <extend_definition comment="Microsoft Windows XP x64 is installed" definition_ref="oval:org.mitre.oval:def:15247"/>
                <extend_definition comment="Microsoft Windows Server 2003 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1870"/>
                <extend_definition comment="Microsoft Windows Server 2003 (x64) is installed" definition_ref="oval:org.mitre.oval:def:730"/>
                <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
                <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
                <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
                <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.19400" test_ref="oval:org.mitre.oval:tst:80810"/>
                <criteria operator="AND" comment="Check for LDR range">
                  <criterion comment="Check for mshtml.dll version greater than or equal to 8.0.6001.23000" test_ref="oval:org.mitre.oval:tst:79301"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.6001.23468" test_ref="oval:org.mitre.oval:tst:80358"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable IE 8 version">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 is installed" definition_ref="oval:org.mitre.oval:def:12541"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 is installed" definition_ref="oval:org.mitre.oval:def:12754"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7600.17209" test_ref="oval:org.mitre.oval:tst:80045"/>
                <criteria operator="AND" comment="Check for LDR">
                  <criterion comment="Mshtml.dll version is greater than or equal 8.0.7600.20000" test_ref="oval:org.mitre.oval:tst:10804"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7600.21419" test_ref="oval:org.mitre.oval:tst:80804"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Win 7 / R2 and vulnerable IE 8 version">
              <criteria operator="OR" comment="Win 7 / R2">
                <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
                <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
                <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed" definition_ref="oval:org.mitre.oval:def:5954"/>
              </criteria>
              <criteria operator="OR" comment="Check for vulnerable version">
                <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.18035" test_ref="oval:org.mitre.oval:tst:80702"/>
                <criteria operator="AND" comment="Check for LDR range">
                  <criterion comment="Mshtml.dll version is greater than or equal to 8.0.7601.21000" test_ref="oval:org.mitre.oval:tst:80043"/>
                  <criterion comment="Check if the version of mshtml.dll is less than 8.0.7601.22199" test_ref="oval:org.mitre.oval:tst:80711"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 9 and vulnerable OS versions">
          <extend_definition comment="Microsoft Internet Explorer 9 is installed" definition_ref="oval:org.mitre.oval:def:11985"/>
          <criteria operator="OR" comment="Vista/2K8/Win7/R2">
            <extend_definition comment="Microsoft Windows 7 is installed" definition_ref="oval:org.mitre.oval:def:12541"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
            <extend_definition comment="Microsoft Windows Vista (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1282"/>
            <extend_definition comment="Microsoft Windows Vista x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:2041"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:4870"/>
            <extend_definition comment="Microsoft Windows Server 2008 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:5356"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.16464" test_ref="oval:org.mitre.oval:tst:80834"/>
            <criteria operator="AND" comment="Check for LDR range">
              <criterion comment="Mshtml.dll version is greater than or equal to 9.0.8112.20000" test_ref="oval:org.mitre.oval:tst:42899"/>
              <criterion comment="Check if the version of mshtml.dll is less than 9.0.8112.20573" test_ref="oval:org.mitre.oval:tst:80592"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="IE 10 and vulnerable OS versions">
          <extend_definition comment="Microsoft Internet Explorer 10 is installed" definition_ref="oval:org.mitre.oval:def:15751"/>
          <criteria operator="OR" comment="Win 8 / 2012">
            <extend_definition comment="Microsoft Windows 8 is installed" definition_ref="oval:org.mitre.oval:def:15732"/>
            <extend_definition comment="Microsoft Windows Server 2012 is installed" definition_ref="oval:org.mitre.oval:def:16359"/>
          </criteria>
          <criteria operator="OR" comment="Check for vulnerable version">
            <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.16494" test_ref="oval:org.mitre.oval:tst:80734"/>
            <criteria operator="AND" comment="Check for LDR range">
              <criterion comment="Check if the version of mshtml.dll is greater than or equal to 10.0.9200.20000" test_ref="oval:org.mitre.oval:tst:80523"/>
              <criterion comment="Check if the version of mshtml.dll is less than 10.0.9200.20599" test_ref="oval:org.mitre.oval:tst:79891"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:16463" version="9" class="vulnerability">
      <metadata>
        <title>Active Directory Buffer Overflow Vulnerability - MS13-032</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2013-1282" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1282"/>
        <description>The LDAP service in Microsoft Active Directory, Active Directory Application Mode (ADAM), Active Directory Lightweight Directory Service (AD LDS), and Active Directory Services allows remote attackers to cause a denial of service (memory consumption and service outage) via a crafted query, aka "Memory Consumption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2013-04-12T09:46:55">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-04-15T21:47:42.538-04:00">DRAFT</status_change>
            <status_change date="2013-05-06T04:02:21.787-04:00">INTERIM</status_change>
            <status_change date="2013-05-27T04:00:08.917-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:16463 - Updated definition (16463) on MS13-032: added NTDS service criteria" date="2013-07-17T15:58:00.728-04:00">
              <contributor organization="SecPod Technologies">Sharath S</contributor>
            </modified>
            <status_change date="2013-07-17T16:11:44.715-04:00">INTERIM</status_change>
            <status_change date="2013-08-05T04:00:11.748-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:16463 - modified vulnerabilities which check the version of file adamdsa.dll" date="2013-12-18T16:36:00.218-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-12-18T16:44:41.262-05:00">INTERIM</status_change>
            <status_change date="2014-01-06T04:00:07.382-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:89195 - bulletin MS14-016, for the month of Mar 2014." date="2014-03-18T14:40:00.553-04:00">
              <contributor organization="SecPod Technologies">Pooja Shetty</contributor>
            </modified>
            <status_change date="2014-03-18T14:42:04.274-04:00">INTERIM</status_change>
            <status_change date="2014-04-07T04:02:00.181-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Win 2k3 vulnerable version">
          <criterion comment="the system is being used as: Member Server, BDC or PDC (DomainRole is 3, 4 or 5)" test_ref="oval:org.mitre.oval:tst:10634"/>
          <criterion comment="NTDS Service is installed" test_ref="oval:org.mitre.oval:tst:42615"/>
          <criterion comment="Check if the version of ntdsa.dll is less than 5.2.3790.5130" test_ref="oval:org.mitre.oval:tst:80895"/>
          <criteria operator="OR" comment="Win 2k3">
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win XP / 2k3 _ADAM file version">
          <criteria operator="OR" comment="Win XP / Win 2K3">
            <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
            <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
          </criteria>
          <criterion comment="Check if ADAM service is installed" test_ref="oval:org.mitre.oval:tst:89195"/>
          <criterion comment="Check if the version of adamdsa.dll is less than 1.1.3790.5131" test_ref="oval:org.mitre.oval:tst:80917"/>
        </criteria>
        <criteria operator="AND" comment="Win 2k8 / Vista and vulnerable version of file">
          <criteria operator="OR" comment="Win Vista / 2K8">
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
          </criteria>
          <criteria operator="OR" comment="Check for LDR/ GDR">
            <criterion comment="Check if the version of ntdsai.dll is less than 6.0.6002.18781" test_ref="oval:org.mitre.oval:tst:80946"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="ntdsai.dll is greater than or equal 6.0.6002.22000" test_ref="oval:org.mitre.oval:tst:10980"/>
              <criterion comment="Check if the version of ntdsai.dll is less than 6.0.6002.23036" test_ref="oval:org.mitre.oval:tst:80541"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 / 2k8 R2 base and vulnerable file version">
          <criteria operator="OR" comment="Win 7 / Win 2k8 R2 base">
            <extend_definition comment="Microsoft Windows 7 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:6165"/>
            <extend_definition comment="Microsoft Windows 7 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:5950"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Edition is installed" definition_ref="oval:org.mitre.oval:def:6438"/>
          </criteria>
          <criteria operator="OR" comment="Check for LDR/GDR">
            <criterion comment="Check if the version of ntdsai.dll is less than 6.1.7600.17232" test_ref="oval:org.mitre.oval:tst:80753"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="ntdsai.dll is greater than or equal 6.1.7600.20000" test_ref="oval:org.mitre.oval:tst:11632"/>
              <criterion comment="Check if the version of ntdsai.dll is less than 6.1.7600.21442" test_ref="oval:org.mitre.oval:tst:80240"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Win 7 SP1 / 2k8 R2 SP1">
          <criteria operator="OR" comment="Win 7 SP1 / Win 2k8 R2 Sp1 and vulnerable version of file">
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12567"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12292"/>
            <extend_definition comment="Microsoft Windows 7 x64 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12627"/>
          </criteria>
          <criteria operator="OR" comment="Check for LDR/GDR">
            <criterion comment="Check if the version of ntdsai.dll is less than 6.1.7601.18075" test_ref="oval:org.mitre.oval:tst:81081"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="ntdsai.dll is greater than or equal 6.1.7601.21000" test_ref="oval:org.mitre.oval:tst:77601"/>
              <criterion comment="Check if the version of ntdsai.dll is less than 6.1.7601.22245" test_ref="oval:org.mitre.oval:tst:81109"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Microsoft Windows 8/2012 and vulnerable file version">
          <criteria operator="OR" comment="Microsoft Windows 8/2012">
            <extend_definition comment="Microsoft Windows 8 is installed" definition_ref="oval:org.mitre.oval:def:15732"/>
            <extend_definition comment="Microsoft Windows Server 2012 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:15585"/>
          </criteria>
          <criteria operator="OR" comment="vulnerable file version">
            <criterion comment="Check if the version of ntdsai.dll is less than 6.2.9200.16522" test_ref="oval:org.mitre.oval:tst:80529"/>
            <criteria operator="AND" comment="Check for LDR">
              <criterion comment="Check if the version of ntdsai.dll is greater than or equal to 6.2.9200.20000" test_ref="oval:org.mitre.oval:tst:80778"/>
              <criterion comment="Check if the version of ntdsai.dll is less than 6.2.9200.20626" test_ref="oval:org.mitre.oval:tst:81046"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:16458" version="3" class="vulnerability">
      <metadata>
        <title>Vulnerability in Windows Kernel could allow elevation of privilege - MS13-017</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2013-1279" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1279"/>
        <description>Race condition in the kernel in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT allows local users to gain privileges via a crafted application that leverages incorrect handling of objects in memory, aka "Kernel Race Condition Vulnerability," a different vulnerability than CVE-2013-1278.</description>
        <oval_repository>
          <dates>
            <submitted date="2013-02-15T10:41:13">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-02-15T17:23:20.895-05:00">DRAFT</status_change>
            <status_change date="2013-03-04T04:01:10.702-05:00">INTERIM</status_change>
            <status_change date="2013-03-25T04:00:51.190-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="win xp sp3/version">
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <criterion comment="Check if the version of Ntoskrnl.exe is less than 5.1.2600.6335" test_ref="oval:org.mitre.oval:tst:80000"/>
        </criteria>
        <criteria operator="AND" comment="win xp sp2 64-bit/server 2003 (32+64)/version">
          <criteria operator="OR" comment="either OS">
            <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
          </criteria>
          <criterion comment="Check if the version of Ntoskrnl.exe is less than 5.2.3790.5107" test_ref="oval:org.mitre.oval:tst:80577"/>
        </criteria>
        <criteria operator="AND" comment="server 2003 ia-64/version">
          <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
          <criterion comment="Check if the version of Ntkrnlmp.exe is less than 5.2.3790.5107" test_ref="oval:org.mitre.oval:tst:80317"/>
        </criteria>
        <criteria operator="AND" comment="vista/server 2008/version">
          <criteria operator="OR" comment="either OS">
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
            <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
          </criteria>
          <criteria operator="OR" comment="GDR/LDR">
            <criterion comment="Check if the version of Ntoskrnl.exe is less than 6.0.6002.18765" test_ref="oval:org.mitre.oval:tst:80860"/>
            <criteria operator="AND" comment="LDR range">
              <criterion comment="Check if the version of Ntoskrnl.exe is less than 6.0.6002.23025" test_ref="oval:org.mitre.oval:tst:80859"/>
              <criterion comment="the version of Ntoskrnl.exe is greater than or equal 6.0.6002.22000" test_ref="oval:org.mitre.oval:tst:10581"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="win 7/server 2008 R2/version">
          <criteria operator="OR" comment="either OS">
            <extend_definition comment="Microsoft Windows 7 is installed" definition_ref="oval:org.mitre.oval:def:12541"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 is installed" definition_ref="oval:org.mitre.oval:def:12754"/>
          </criteria>
          <criteria operator="OR" comment="GDR/LDR">
            <criterion comment="Check if the version of Ntoskrnl.exe is less than 6.1.7600.17207" test_ref="oval:org.mitre.oval:tst:80912"/>
            <criteria operator="AND" comment="LDR range">
              <criterion comment="Check if the version of Ntoskrnl.exe is less than 6.1.7600.21417" test_ref="oval:org.mitre.oval:tst:80332"/>
              <criterion comment="the version of Ntoskrnl.exe is greater than or equal 6.1.7600.20000" test_ref="oval:org.mitre.oval:tst:20969"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="win 7 sp1/server 2008 R2 sp1/version">
          <criteria operator="OR" comment="either OS">
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12583"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12567"/>
            <extend_definition comment="Microsoft Windows 7 x64 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12627"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12292"/>
          </criteria>
          <criteria operator="OR" comment="GDR/LDR">
            <criterion comment="Check if the version of Ntoskrnl.exe is less than 6.1.7601.18044" test_ref="oval:org.mitre.oval:tst:80674"/>
            <criteria operator="AND" comment="LDR range">
              <criterion comment="Check if the version of Ntoskrnl.exe is less than 6.1.7601.22210" test_ref="oval:org.mitre.oval:tst:80383"/>
              <criterion comment="the version of Ntoskrnl.exe is greater than or equal 6.1.7601.21000" test_ref="oval:org.mitre.oval:tst:43904"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="win 8/server 2012/version">
          <criteria operator="OR" comment="either OS">
            <extend_definition comment="Microsoft Windows 8 is installed" definition_ref="oval:org.mitre.oval:def:15732"/>
            <extend_definition comment="Microsoft Windows Server 2012 is installed" definition_ref="oval:org.mitre.oval:def:16359"/>
          </criteria>
          <criteria operator="OR" comment="GDR/LDR">
            <criterion comment="Check if the version of Ntoskrnl.exe is less than 6.2.9200.16496" test_ref="oval:org.mitre.oval:tst:80936"/>
            <criteria operator="AND" comment="LDR range">
              <criterion comment="Check if the version of Ntoskrnl.exe is less than 6.2.9200.20605" test_ref="oval:org.mitre.oval:tst:80907"/>
              <criterion comment="Check if the version of Ntoskrnl.exe is greater than or equal to 6.2.9200.20000" test_ref="oval:org.mitre.oval:tst:80722"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:16455" version="3" class="vulnerability">
      <metadata>
        <title>Kernel Race Condition Vulnerability - CVE-2013-1284 (MS13-031)</title>
        <affected family="windows">
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2012</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2013-1284" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1284"/>
        <description>Race condition in the kernel in Microsoft Windows 8, Windows Server 2012, and Windows RT allows local users to gain privileges via a crafted application that leverages improper handling of objects in memory, aka "Kernel Race Condition Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2013-04-12T15:29:18">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-04-15T21:41:30.446-04:00">DRAFT</status_change>
            <status_change date="2013-05-06T04:02:20.591-04:00">INTERIM</status_change>
            <status_change date="2013-05-27T04:00:08.505-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="Win 8 / 2012">
          <extend_definition comment="Microsoft Windows 8 is installed" definition_ref="oval:org.mitre.oval:def:15732"/>
          <extend_definition comment="Microsoft Windows Server 2012 is installed" definition_ref="oval:org.mitre.oval:def:16359"/>
        </criteria>
        <criteria operator="OR" comment="Check for vulnerable version">
          <criterion comment="Check if the version of ntoskrnl.exe is less than 6.2.9200.16551" test_ref="oval:org.mitre.oval:tst:80720"/>
          <criteria operator="AND" comment="Check for LDR">
            <criterion comment="Check if the version of Ntoskrnl.exe is greater than or equal to 6.2.9200.20000" test_ref="oval:org.mitre.oval:tst:80722"/>
            <criterion comment="Check if the version of ntoskrnl.exe is less than 6.2.9200.20655" test_ref="oval:org.mitre.oval:tst:80310"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:16448" version="3" class="vulnerability">
      <metadata>
        <title>Vulnerability in Windows Kernel could allow elevation of privilege - MS13-017</title>
        <affected family="windows">
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2013-1280" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1280"/>
        <description>The kernel in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT does not properly handle objects in memory, which allows local users to gain privileges via a crafted application, aka "Windows Kernel Reference Count Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2013-02-15T10:41:13">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-02-15T17:23:21.550-05:00">DRAFT</status_change>
            <status_change date="2013-03-04T04:01:09.255-05:00">INTERIM</status_change>
            <status_change date="2013-03-25T04:00:49.923-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="win xp sp3/version">
          <extend_definition comment="Microsoft Windows XP (x86) SP3 is installed" definition_ref="oval:org.mitre.oval:def:5631"/>
          <criterion comment="Check if the version of Ntoskrnl.exe is less than 5.1.2600.6335" test_ref="oval:org.mitre.oval:tst:80000"/>
        </criteria>
        <criteria operator="AND" comment="win xp sp2 64-bit/server 2003 (32+64)/version">
          <criteria operator="OR" comment="either OS">
            <extend_definition comment="Microsoft Windows XP x64 Edition SP2 is installed" definition_ref="oval:org.mitre.oval:def:4193"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1935"/>
            <extend_definition comment="Microsoft Windows Server 2003 SP2 (x64) is installed" definition_ref="oval:org.mitre.oval:def:2161"/>
          </criteria>
          <criterion comment="Check if the version of Ntoskrnl.exe is less than 5.2.3790.5107" test_ref="oval:org.mitre.oval:tst:80577"/>
        </criteria>
        <criteria operator="AND" comment="server 2003 ia-64/version">
          <extend_definition comment="Microsoft Windows Server 2003 (ia64) SP2 is installed" definition_ref="oval:org.mitre.oval:def:1442"/>
          <criterion comment="Check if the version of Ntkrnlmp.exe is less than 5.2.3790.5107" test_ref="oval:org.mitre.oval:tst:80317"/>
        </criteria>
        <criteria operator="AND" comment="vista/server 2008/version">
          <criteria operator="OR" comment="either OS">
            <extend_definition comment="Microsoft Windows Vista x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5594"/>
            <extend_definition comment="Microsoft Windows Vista (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6124"/>
            <extend_definition comment="Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:5653"/>
            <extend_definition comment="Microsoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6150"/>
            <extend_definition comment="Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed" definition_ref="oval:org.mitre.oval:def:6216"/>
          </criteria>
          <criteria operator="OR" comment="GDR/LDR">
            <criterion comment="Check if the version of Ntoskrnl.exe is less than 6.0.6002.18765" test_ref="oval:org.mitre.oval:tst:80860"/>
            <criteria operator="AND" comment="LDR range">
              <criterion comment="Check if the version of Ntoskrnl.exe is less than 6.0.6002.23025" test_ref="oval:org.mitre.oval:tst:80859"/>
              <criterion comment="the version of Ntoskrnl.exe is greater than or equal 6.0.6002.22000" test_ref="oval:org.mitre.oval:tst:10581"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="win 7/server 2008 R2/version">
          <criteria operator="OR" comment="either OS">
            <extend_definition comment="Microsoft Windows 7 is installed" definition_ref="oval:org.mitre.oval:def:12541"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 is installed" definition_ref="oval:org.mitre.oval:def:12754"/>
          </criteria>
          <criteria operator="OR" comment="GDR/LDR">
            <criterion comment="Check if the version of Ntoskrnl.exe is less than 6.1.7600.17207" test_ref="oval:org.mitre.oval:tst:80912"/>
            <criteria operator="AND" comment="LDR range">
              <criterion comment="Check if the version of Ntoskrnl.exe is less than 6.1.7600.21417" test_ref="oval:org.mitre.oval:tst:80332"/>
              <criterion comment="the version of Ntoskrnl.exe is greater than or equal 6.1.7600.20000" test_ref="oval:org.mitre.oval:tst:20969"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="win 7 sp1/server 2008 R2 sp1/version">
          <criteria operator="OR" comment="either OS">
            <extend_definition comment="Microsoft Windows Server 2008 R2 Itanium-Based Edition Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12583"/>
            <extend_definition comment="Microsoft Windows Server 2008 R2 x64 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12567"/>
            <extend_definition comment="Microsoft Windows 7 x64 Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12627"/>
            <extend_definition comment="Microsoft Windows 7 (32-bit) Service Pack 1 is installed" definition_ref="oval:org.mitre.oval:def:12292"/>
          </criteria>
          <criteria operator="OR" comment="GDR/LDR">
            <criterion comment="Check if the version of Ntoskrnl.exe is less than 6.1.7601.18044" test_ref="oval:org.mitre.oval:tst:80674"/>
            <criteria operator="AND" comment="LDR range">
              <criterion comment="Check if the version of Ntoskrnl.exe is less than 6.1.7601.22210" test_ref="oval:org.mitre.oval:tst:80383"/>
              <criterion comment="the version of Ntoskrnl.exe is greater than or equal 6.1.7601.21000" test_ref="oval:org.mitre.oval:tst:43904"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="win 8/server 2012/version">
          <criteria operator="OR" comment="either OS">
            <extend_definition comment="Microsoft Windows 8 is installed" definition_ref="oval:org.mitre.oval:def:15732"/>
            <extend_definition comment="Microsoft Windows Server 2012 is installed" definition_ref="oval:org.mitre.oval:def:16359"/>
          </criteria>
          <criteria operator="OR" comment="GDR/LDR">
            <criterion comment="Check if the version of Ntoskrnl.exe is less than 6.2.9200.16496" test_ref="oval:org.mitre.oval:tst:80936"/>
            <criteria operator="AND" comment="LDR range">
              <criterion comment="Check if the version of Ntoskrnl.exe is less than 6.2.9200.20605" test_ref="oval:org.mitre.oval:tst:80907"/>
              <criterion comment="Check if the version of Ntoskrnl.exe is greater than or equal to 6.2.9200.20000" test_ref="oval:org.mitre.oval:tst:80722"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:16445" version="5" class="vulnerability">
      <metadata>
        <title>SharePoint Directory Traversal Vulnerability - MS13-024</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows 8</platform>
          <platform>Microsoft Windows 7</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Server 2008 R2</platform>
          <platform>Microsoft Windows Server 2012</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft SharePoint Foundation 2010</product>
          <product>Microsoft SharePoint Server 2010</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2013-0084" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0084"/>
        <description>Directory traversal vulnerability in Microsoft SharePoint Server 2010 SP1 and SharePoint Foundation 2010 SP1 allows remote attackers to bypass intended read restrictions for content, and hijack user accounts, via a crafted URL, aka "SharePoint Directory Traversal Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2013-03-14T12:59:10">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2013-03-18T14:52:41.326-04:00">DRAFT</status_change>
            <status_change date="2013-04-08T04:00:29.945-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:17:05.574-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:var:1390 - November 2014 bulletins." date="2014-11-17T17:25:00.386-05:00">
              <contributor organization="SecPod Technologies">Kumarswamy S</contributor>
            </modified>
            <status_change date="2014-11-17T17:29:49.054-05:00">INTERIM</status_change>
            <status_change date="20